Техническая информация
- <SYSTEM32>\svchost.exe
- %TEMP%\nss6fc3.tmp
- %TEMP%\nsi6fd4.tmp\system.dll
- <DRIVERS>\etc\hosts-wintousb
- %TEMP%\nsi6fd4.tmp\nsexec.dll
- %TEMP%\nsi6fd4.tmp\registry.dll
- <DRIVERS>\etc\hosts-wintousb
- %TEMP%\nsi6fd4.tmp\nsexec.dll
- %TEMP%\nsi6fd4.tmp\registry.dll
- %TEMP%\nsi6fd4.tmp\system.dll
- '%WINDIR%\syswow64\cmd.exe' /c "echo 0.0.0.0 www.ea###efi.com>> <DRIVERS>\etc\hosts"' (со скрытым окном)
- '<SYSTEM32>\cofire.exe' "<SYSTEM32>\sysmain.dll" "<SYSTEM32>\svchost.exe"
- '%WINDIR%\syswow64\cmd.exe' /c "echo 0.0.0.0 www.ea###efi.com>> <DRIVERS>\etc\hosts"
- '<SYSTEM32>\cofire.exe' "<SYSTEM32>\rpcss.dll" "<SYSTEM32>\svchost.exe"