Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nsx1278.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\new feature\vpn.exe
- %TEMP%\new feature\4.exe
- %TEMP%\7zipsfx.000\consolarmi.xlm
- %TEMP%\7zipsfx.000\ingannaste.xlm
- %TEMP%\7zipsfx.000\mare.xlm
- %TEMP%\7zipsfx.000\udi.xlm
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\7zipsfx.000\affannosa.exe.com
- %TEMP%\7zipsfx.000\h
- %TEMP%\nsx1278.tmp\uac.dll
- %TEMP%\7zipsfx.000\h
- %TEMP%\7zipsfx.000\consolarmi.xlm
- %TEMP%\7zipsfx.000\affannosa.exe.com
- DNS ASK vM##########QzFIwevo.vMamJEiRFAhIQzFIwevo
- '%TEMP%\new feature\vpn.exe'
- '%TEMP%\new feature\4.exe'
- '%TEMP%\7zipsfx.000\affannosa.exe.com' H
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Udi.xlm' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Udi.xlm
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^RQWNhxUdVtOmRwinwWDayvrHkBJfQpySTbClIcHUHAqFnIsjLGyajhfxNfBMLFmMZVGznXPFgILFcboClvEltMFFiivzTVpwwgGCeXONRmtD$" Ingannaste.xlm
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 30
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\xhkumtq.vbs"