Техническая информация
- <SYSTEM32>\tasks\<Имя файла>
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\taskhost
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %WINDIR%\web\wallpaper\architecture\<Имя файла>.exe
- C:\users\public\dni9d0tibb
- C:\users\public\g9atahmnv2
- C:\users\public\j3itqjdpsy
- C:\users\public\dxqmnep66h
- C:\users\public\rxfkuq2y2e
- C:\users\public\nzuogdctxn
- C:\users\public\4rygjvbbe7
- C:\users\public\vcq49o4o1i
- C:\users\public\lm5hwecf2l
- C:\users\public\opyd0wft4w
- C:\users\public\qdhemhjzcp
- C:\users\public\iyd7dvvud3
- C:\users\public\jhjpxqsaxt
- C:\users\public\cjhljzwkpt
- %ProgramFiles%\drweb32w\b75386f1303e64d8139363b71e44ac16341adf4e
- %ProgramFiles%\drweb32w\taskhost.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\cc11b995f2a76da408ea6a601e682e64743153ad
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\winlogon.exe
- <SYSTEM32>\djoin\cc11b995f2a76da408ea6a601e682e64743153ad
- <SYSTEM32>\djoin\winlogon.exe
- %WINDIR%\web\wallpaper\architecture\39362fde53cb4e1e03f28b7f16bd739c622bcffa
- C:\users\public\xfwqdxowek
- C:\users\public\nmfeyewxmg
- C:\users\public\cjhljzwkpt
- C:\users\public\jhjpxqsaxt
- C:\users\public\iyd7dvvud3
- C:\users\public\qdhemhjzcp
- C:\users\public\opyd0wft4w
- C:\users\public\lm5hwecf2l
- C:\users\public\vcq49o4o1i
- C:\users\public\4rygjvbbe7
- C:\users\public\nzuogdctxn
- C:\users\public\rxfkuq2y2e
- C:\users\public\dxqmnep66h
- C:\users\public\j3itqjdpsy
- C:\users\public\g9atahmnv2
- C:\users\public\dni9d0tibb
- C:\users\public\xfwqdxowek
- C:\users\public\nmfeyewxmg
- 'da######3.000webhostapp.com':443
- 'ip##fo.io':443
- 'da######3.000webhostapp.com':443
- 'ip##fo.io':443
- DNS ASK da######3.000webhostapp.com
- DNS ASK ip##fo.io
- '%ProgramFiles%\drweb32w\taskhost.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "<Имя файла>" /sc ONLOGON /tr "'%WINDIR%\Web\Wallpaper\Architecture\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'<SYSTEM32>\djoin\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhost" /sc ONLOGON /tr "'%ProgramFiles%\drweb32w\taskhost.exe'" /rl HIGHEST /f