Техническая информация
- '%TEMP%\install.exe'
- '%TEMP%\mboeojrnaoeanjtn.exe' yoqaafc.bat++install.exe
- '<SYSTEM32>\taskkill.exe' /f /im "praetorian.exe"
- '<SYSTEM32>\chcp.com' 866
- '<SYSTEM32>\cmd.exe' /c yoqaafc.bat
- <DRIVERS>\etc\hоsts
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bRCa8q0cN8P0C5uX0A5xI0vMhC081D60kBtN0nBWe0Ao7R10ZAd114Rg03jc7[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\XSvAp10CntO0u6uc00gIr0RwYy0dk7H0dWn811ell0pDo316N9b0yiD102zzO[1]
- %TEMP%\install.exe
- %TEMP%\mboeojrnaoeanjtn.exe
- %TEMP%\yoqaafc.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\XSvAp10CntO0u6uc00gIr0RwYy0dk7H0dWn811ell0pDo316N9b0yiD102zzO[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bRCa8q0cN8P0C5uX0A5xI0vMhC081D60kBtN0nBWe0Ao7R10ZAd114Rg03jc7[1]
- 're###ncefile.ru':80
- 'go###ebot.com':80
- re###ncefile.ru/XSvAp10CntO0u6uc00gIr0RwYy0dk7H0dWn811ell0pDo316N9b0yiD102zzO
- go###ebot.com/bRCa8q0cN8P0C5uX0A5xI0vMhC081D60kBtN0nBWe0Ao7R10ZAd114Rg03jc7
- DNS ASK re###ncefile.ru
- DNS ASK go###ebot.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''