Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Host' = '%ALLUSERSPROFILE%\Windows Host\Windows Host.exe'
- firefox.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %ALLUSERSPROFILE%\2840636.exe
- %ALLUSERSPROFILE%\44\5f43cdc831ec0ee586b187d86beebfca.txt
- %ALLUSERSPROFILE%\44\da67e9e16ae600f892e7d35536efdf52.txt
- %ALLUSERSPROFILE%\44\cd4af104debb9de380cb9a38e9b8c40d.txt
- %ALLUSERSPROFILE%\44\991d026cda89352b065d342d54a564b4.txt
- %ALLUSERSPROFILE%\44\nss3.dll
- %ALLUSERSPROFILE%\44\msvcp140.dll
- %ALLUSERSPROFILE%\44\ec4c16dd6fa6c03b2a32619947cf781f.txt
- %ALLUSERSPROFILE%\44\mozglue.dll
- %ALLUSERSPROFILE%\44\vcruntime140.dll
- %ALLUSERSPROFILE%\44\sqlite3.dll
- %ALLUSERSPROFILE%\44\softokn3.dll
- %ALLUSERSPROFILE%\4446
- %ALLUSERSPROFILE%\windows host\windows host.exe
- %ALLUSERSPROFILE%\6538875.exe
- %ALLUSERSPROFILE%\44\freebl3.dll
- %ALLUSERSPROFILE%\44\48d1c56ba6328c8bb7968cc63c9449c3.txt
- %ALLUSERSPROFILE%\windows host\windows host.exe
- %ALLUSERSPROFILE%\44\48d1c56ba6328c8bb7968cc63c9449c3.txt
- %ALLUSERSPROFILE%\44\5f43cdc831ec0ee586b187d86beebfca.txt
- %ALLUSERSPROFILE%\44\991d026cda89352b065d342d54a564b4.txt
- %ALLUSERSPROFILE%\44\cd4af104debb9de380cb9a38e9b8c40d.txt
- %ALLUSERSPROFILE%\44\da67e9e16ae600f892e7d35536efdf52.txt
- %ALLUSERSPROFILE%\44\ec4c16dd6fa6c03b2a32619947cf781f.txt
- %ALLUSERSPROFILE%\44\freebl3.dll
- %ALLUSERSPROFILE%\44\mozglue.dll
- %ALLUSERSPROFILE%\44\msvcp140.dll
- %ALLUSERSPROFILE%\44\nss3.dll
- %ALLUSERSPROFILE%\44\softokn3.dll
- %ALLUSERSPROFILE%\44\sqlite3.dll
- %ALLUSERSPROFILE%\44\vcruntime140.dll
- %ALLUSERSPROFILE%\4446
- 'mi####dollars.xyz':443
- 'ip###ger.org':443
- 'microsoft.com':80
- 'mi####dollars.xyz':443
- 'ip###ger.org':443
- 'st###hamm3r.xyz':443
- DNS ASK mi####dollars.xyz
- DNS ASK ip###ger.org
- DNS ASK st###hamm3r.xyz
- DNS ASK microsoft.com
- '%ALLUSERSPROFILE%\2840636.exe'
- '%ALLUSERSPROFILE%\6538875.exe'
- '%ALLUSERSPROFILE%\windows host\windows host.exe'