Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nshb53c.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\new feature\4.exe
- %TEMP%\new feature\vpn.exe
- %TEMP%\7zipsfx.000\confusione.mpeg
- %TEMP%\7zipsfx.000\dipinte.mpeg
- %TEMP%\7zipsfx.000\estate.mpeg
- %TEMP%\7zipsfx.000\una.mpeg
- %TEMP%\7zipsfx.000\illusione.exe.com
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\7zipsfx.000\p
- %TEMP%\nshb53c.tmp\uac.dll
- %TEMP%\7zipsfx.000\p
- %TEMP%\7zipsfx.000\una.mpeg
- %TEMP%\7zipsfx.000\confusione.mpeg
- %TEMP%\7zipsfx.000\dipinte.mpeg
- %TEMP%\7zipsfx.000\estate.mpeg
- %TEMP%\7zipsfx.000\illusione.exe.com
- DNS ASK eP#####bKR.ePUtfKtbKR
- '%TEMP%\new feature\4.exe'
- '%TEMP%\new feature\vpn.exe'
- '%TEMP%\7zipsfx.000\illusione.exe.com' P
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\dllhost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Dipinte.mpeg' (со скрытым окном)
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Dipinte.mpeg
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^NXhKfUxiyDRVgIudfUJQqTVfTcVwfaBSTQjHDzhxixsJemFIsDmgqnKTeYRUYzRMeYebcnNWGgIFCkhxQhJMSjSxyzFFBzvNDEHrvihTPCHLPtdQKbtLJyTPuHawTixhSU$" Confusione.mpeg
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 30