Техническая информация
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\iexplore
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsass.exe
- C:\users\public\fva7ukvm5z
- C:\users\public\wzsvvhripa
- C:\users\public\mihol0akzt
- C:\users\public\bbbe6n3yvy
- C:\users\public\s3stfjflwn
- C:\users\public\cnr2dki3bi
- C:\users\public\bk1ujl7nkv
- C:\users\public\wiaodrdd4e
- C:\users\public\mvi8ovjvaj
- C:\users\public\obsebt7i1j
- C:\users\public\cavm4sgo8z
- C:\users\public\u0vhmcjdtz
- C:\users\public\i32oxrbhll
- C:\users\public\jypi0ge6kq
- %ProgramFiles(x86)%\internet explorer\jsprofilerui\9db6e019d4f04ef534d0f91b3462d805c40e9d20
- %ProgramFiles(x86)%\internet explorer\jsprofilerui\iexplore.exe
- C:\perflogs\admin\6cb0b6c459d5d3455a3da700e713f2e2529862ff
- C:\perflogs\admin\dwm.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\6203df4a6bafc7c328ee7f6f8ca0a8a838a8a1b9
- C:\users\public\qthmvkvnhp
- C:\users\public\ifvdrlsqtz
- C:\users\public\jypi0ge6kq
- C:\users\public\i32oxrbhll
- C:\users\public\u0vhmcjdtz
- C:\users\public\cavm4sgo8z
- C:\users\public\obsebt7i1j
- C:\users\public\mvi8ovjvaj
- C:\users\public\wiaodrdd4e
- C:\users\public\bk1ujl7nkv
- C:\users\public\cnr2dki3bi
- C:\users\public\s3stfjflwn
- C:\users\public\bbbe6n3yvy
- C:\users\public\mihol0akzt
- C:\users\public\wzsvvhripa
- C:\users\public\fva7ukvm5z
- C:\users\public\qthmvkvnhp
- C:\users\public\ifvdrlsqtz
- '94.##0.248.158':80
- 'ip##fo.io':443
- http://94.##0.248.158/protectWindows.php?x4######################################################################################################################################################...
- DNS ASK ip##fo.io
- '%ProgramFiles(x86)%\internet explorer\jsprofilerui\iexplore.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'C:\PerfLogs\Admin\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Internet Explorer\jsprofilerui\iexplore.exe'" /rl HIGHEST /f