Техническая информация
- <SYSTEM32>\tasks\wmiprvse
- <SYSTEM32>\tasks\lsm
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\lsass
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %ProgramFiles%\luna\wmiprvse.exe
- %TEMP%\qqpkoudd7n
- %TEMP%\fb1htmnrmt
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %TEMP%\dmtmshmurf
- %TEMP%\9wwunqajf6
- %TEMP%\4rwtdj8een
- %TEMP%\q0yl3srpmt
- %TEMP%\eaapdpuuxo
- %TEMP%\1itqqs8jag
- %TEMP%\wg1zxb6kyx
- %TEMP%\oyhrynial4
- %TEMP%\qekzdn4iey
- %TEMP%\uhd438g2dj
- %TEMP%\03kvmfatkf
- %ProgramFiles%\pavfnsvr\6203df4a6bafc7c328ee7f6f8ca0a8a838a8a1b9
- %ProgramFiles%\pavfnsvr\lsass.exe
- C:\totalcmd\language\cc11b995f2a76da408ea6a601e682e64743153ad
- C:\totalcmd\language\winlogon.exe
- C:\msocache\all users\101b941d020240259ca4912829b53995ad543df6
- C:\msocache\all users\lsm.exe
- %ProgramFiles%\luna\24dbde2999530ef5fd907494bc374d663924116c
- %TEMP%\bnjiqby9ly
- %TEMP%\gom9hieobb
- %TEMP%\03kvmfatkf
- %TEMP%\uhd438g2dj
- %TEMP%\qekzdn4iey
- %TEMP%\oyhrynial4
- %TEMP%\bnjiqby9ly
- %TEMP%\wg1zxb6kyx
- %TEMP%\eaapdpuuxo
- %TEMP%\q0yl3srpmt
- %TEMP%\4rwtdj8een
- %TEMP%\9wwunqajf6
- %TEMP%\dmtmshmurf
- %TEMP%\fb1htmnrmt
- %TEMP%\qqpkoudd7n
- %TEMP%\1itqqs8jag
- %TEMP%\gom9hieobb
- '18#.#46.156.15':80
- 'ip##fo.io':443
- http://18#.#46.156.15/kkzbutarur/gxflwgrqvht6wno/4a5b6c699481fdd8151fe698c2faac2f67b7944b.php?kZ#################################################################################################...
- http://18#.#46.156.15/kkzbutarur/gxflwgrqvht6wno/0v7y2i9co/9eae0bb3213ac2993db81861b52b2862.php?kZ###############################################################################################...
- DNS ASK ip##fo.io
- '%ProgramFiles%\pavfnsvr\lsass.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "WmiPrvSE" /sc ONLOGON /tr "'%ProgramFiles%\Luna\WmiPrvSE.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "lsm" /sc ONLOGON /tr "'C:\MSOCache\All Users\lsm.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\winlogon.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'%ProgramFiles%\PavFnSvr\lsass.exe'" /rl HIGHEST /f