Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Host' = '%ALLUSERSPROFILE%\Windows Host\Windows Host.exe'
- firefox.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %ALLUSERSPROFILE%\6544427.exe
- %ALLUSERSPROFILE%\66\d1702755719a72fb090b3dff8a8937f0.txt
- %ALLUSERSPROFILE%\66\6a06de19242c0ee63a113230fbdf44e3.txt
- %ALLUSERSPROFILE%\66\e99c8db0d34fb6d0f1b786f6da0c780e.txt
- %ALLUSERSPROFILE%\66\283ffb66e904bbc8a950ccecc95a4acd.txt
- %ALLUSERSPROFILE%\66\nss3.dll
- %ALLUSERSPROFILE%\66\msvcp140.dll
- %ALLUSERSPROFILE%\66\eb38e4babba3c4c019c87af3a9ec2890.txt
- %ALLUSERSPROFILE%\66\mozglue.dll
- %ALLUSERSPROFILE%\66\vcruntime140.dll
- %ALLUSERSPROFILE%\66\sqlite3.dll
- %ALLUSERSPROFILE%\66\softokn3.dll
- %ALLUSERSPROFILE%\6680
- %ALLUSERSPROFILE%\windows host\windows host.exe
- %ALLUSERSPROFILE%\7299136.exe
- %ALLUSERSPROFILE%\66\freebl3.dll
- %ALLUSERSPROFILE%\66\f3584afab390bc79678c8a9a713109b3.txt
- %ALLUSERSPROFILE%\windows host\windows host.exe
- %ALLUSERSPROFILE%\66\283ffb66e904bbc8a950ccecc95a4acd.txt
- %ALLUSERSPROFILE%\66\6a06de19242c0ee63a113230fbdf44e3.txt
- %ALLUSERSPROFILE%\66\d1702755719a72fb090b3dff8a8937f0.txt
- %ALLUSERSPROFILE%\66\e99c8db0d34fb6d0f1b786f6da0c780e.txt
- %ALLUSERSPROFILE%\66\eb38e4babba3c4c019c87af3a9ec2890.txt
- %ALLUSERSPROFILE%\66\f3584afab390bc79678c8a9a713109b3.txt
- %ALLUSERSPROFILE%\66\freebl3.dll
- %ALLUSERSPROFILE%\66\mozglue.dll
- %ALLUSERSPROFILE%\66\msvcp140.dll
- %ALLUSERSPROFILE%\66\nss3.dll
- %ALLUSERSPROFILE%\66\softokn3.dll
- %ALLUSERSPROFILE%\66\sqlite3.dll
- %ALLUSERSPROFILE%\66\vcruntime140.dll
- %ALLUSERSPROFILE%\6680
- 'mi####dollars.xyz':443
- 'ip###ger.org':443
- 'microsoft.com':80
- 'mi####dollars.xyz':443
- 'ip###ger.org':443
- 'st###hamm3r.xyz':443
- DNS ASK mi####dollars.xyz
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- DNS ASK st###hamm3r.xyz
- '%ALLUSERSPROFILE%\6544427.exe'
- '%ALLUSERSPROFILE%\7299136.exe'
- '%ALLUSERSPROFILE%\windows host\windows host.exe'