Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\prosper3512.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\autochk.exe
- %APPDATA%\prosper3512.exe
- %TEMP%\nshc10e.tmp
- %TEMP%\02vqprgl0atfidc
- %TEMP%\wkxohdeyqvvyr
- %TEMP%\nsxc11f.tmp\system.dll
- %APPDATA%\prosper3512.exe
- 'ca##inz.ga':80
- 'up###esz.com':80
- 'kl#####gcleaning.com':80
- 'ms##2.com':80
- 'bu###r-ff.com':80
- 'te#####arningpods.com':80
- DNS ASK ca##inz.ga
- DNS ASK up###esz.com
- DNS ASK kl#####gcleaning.com
- DNS ASK ms##2.com
- DNS ASK bu###r-ff.com
- DNS ASK te#####arningpods.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\prosper3512.exe"