Техническая информация
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\wmiprvse
- <SYSTEM32>\tasks\lsm
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\csrss
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\lsass.exe
- C:\users\public\z90vesfiyo
- C:\users\public\kboewbnhm4
- C:\users\public\o7dehkms0g
- C:\users\public\orkmhbgwhs
- C:\users\public\aej62lntks
- C:\users\public\aql6qxqhot
- C:\users\public\gxeefctbds
- C:\users\public\9hxhaypg41
- C:\users\public\k8yoybrmvi
- C:\users\public\jzrzmgetz2
- C:\users\public\x55tfdfkok
- C:\users\public\vtyisfli38
- C:\users\public\x8vsekws9e
- C:\users\public\srb0ypqwrm
- C:\totalcmd\language\886983d96e3d3e31032c679b2d4ea91b6c05afef
- C:\totalcmd\language\csrss.exe
- <SYSTEM32>\wmerror\6cb0b6c459d5d3455a3da700e713f2e2529862ff
- <SYSTEM32>\wmerror\dwm.exe
- <SYSTEM32>\nlhtml\101b941d020240259ca4912829b53995ad543df6
- <SYSTEM32>\nlhtml\lsm.exe
- <SYSTEM32>\wbem\ppcrsopcompschema\24dbde2999530ef5fd907494bc374d663924116c
- <SYSTEM32>\wbem\ppcrsopcompschema\wmiprvse.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\6203df4a6bafc7c328ee7f6f8ca0a8a838a8a1b9
- C:\users\public\0dz5ecbezr
- C:\users\public\8edniwnfqq
- C:\users\public\srb0ypqwrm
- C:\users\public\x8vsekws9e
- C:\users\public\vtyisfli38
- C:\users\public\x55tfdfkok
- C:\users\public\jzrzmgetz2
- C:\users\public\k8yoybrmvi
- C:\users\public\9hxhaypg41
- C:\users\public\gxeefctbds
- C:\users\public\aql6qxqhot
- C:\users\public\aej62lntks
- C:\users\public\orkmhbgwhs
- C:\users\public\o7dehkms0g
- C:\users\public\kboewbnhm4
- C:\users\public\z90vesfiyo
- C:\users\public\0dz5ecbezr
- C:\users\public\8edniwnfqq
- 'pn#.#k-one.ru':80
- 'ip##fo.io':443
- http://pn#.#k-one.ru/jsProcessorbigloadflower.php?hL#############################################################################################################################################...
- DNS ASK pn#.#k-one.ru
- DNS ASK ip##fo.io
- 'C:\totalcmd\language\csrss.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WmiPrvSE" /sc ONLOGON /tr "'<SYSTEM32>\wbem\ppcRsopCompSchema\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc ONLOGON /tr "'<SYSTEM32>\nlhtml\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'<SYSTEM32>\wmerror\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\csrss.exe'" /rl HIGHEST /f