Техническая информация
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\services
- <SYSTEM32>\tasks\mdm
- <Имя диска съемного носителя>:\autorun.inf
- <Имя диска съемного носителя>:\mdm.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- ClassName: 'OLLYDBG', WindowName: ''
- %WINDIR%\syswow64\bopomofo\winlogon.exe
- C:\users\public\wu5ssqz5ll
- C:\users\public\ehbzswd1jl
- C:\users\public\bee7eppx6s
- C:\users\public\2p10ltsyci
- C:\users\public\umq9my0nyd
- C:\users\public\frvwek1edl
- C:\users\public\8u1wjn8uwk
- C:\users\public\y0iawbkbs5
- C:\users\public\ut2jdkkmvz
- C:\users\public\gybjcoajzb
- C:\users\public\5zombvf0ao
- C:\users\public\9c7t3clb82
- C:\users\public\t6oovelccf
- C:\users\public\jze1sgvp1u
- %CommonProgramFiles(x86)%\microsoft shared\vs7debug\coloader\559fba5f8e44108851927af432f0edac6117c574
- %CommonProgramFiles(x86)%\microsoft shared\vs7debug\coloader\mdm.exe
- %WINDIR%\syswow64\els\c5b4cb5e9653cce737f29f72ba880dd4c4bab27d
- %WINDIR%\syswow64\els\services.exe
- %ProgramFiles(x86)%\internet explorer\sqmapi\9db6e019d4f04ef534d0f91b3462d805c40e9d20
- %ProgramFiles(x86)%\internet explorer\sqmapi\iexplore.exe
- %WINDIR%\syswow64\bopomofo\cc11b995f2a76da408ea6a601e682e64743153ad
- C:\users\public\rdcfkqssfh
- C:\users\public\sdrq8uobiy
- <Имя диска съемного носителя>:\autorun.inf
- <Имя диска съемного носителя>:\mdm.exe
- C:\users\public\jze1sgvp1u
- C:\users\public\t6oovelccf
- C:\users\public\9c7t3clb82
- C:\users\public\5zombvf0ao
- C:\users\public\gybjcoajzb
- C:\users\public\ut2jdkkmvz
- C:\users\public\y0iawbkbs5
- C:\users\public\8u1wjn8uwk
- C:\users\public\frvwek1edl
- C:\users\public\umq9my0nyd
- C:\users\public\2p10ltsyci
- C:\users\public\bee7eppx6s
- C:\users\public\ehbzswd1jl
- C:\users\public\wu5ssqz5ll
- C:\users\public\rdcfkqssfh
- C:\users\public\sdrq8uobiy
- '18#.#46.67.181':80
- 'ap#.##legram.org':443
- 'ip##fo.io':443
- http://18#.#46.67.181/pythonGeoBigloadServer.php?9g##############################################################################################################################################...
- DNS ASK ap#.##legram.org
- DNS ASK ip##fo.io
- '%CommonProgramFiles(x86)%\microsoft shared\vs7debug\coloader\mdm.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'<SYSTEM32>\bopomofo\winlogon.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Internet Explorer\sqmapi\iexplore.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "services" /sc ONLOGON /tr "'<SYSTEM32>\els\services.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "mdm" /sc ONLOGON /tr "'%CommonProgramFiles(x86)%\microsoft shared\VS7Debug\coloader\mdm.exe'" /rl HIGHEST /f