Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%LOCALAPPDATA%\firefox.exe"'
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %TEMP%\wwigrjchqaquoowjokay fb.exe
- %LOCALAPPDATA%\firefox.exe
- %APPDATA%\remcos\logs.dat
- %TEMP%\wwigrjchqaquoowjokay fb.exe
- 'em######nglatakva.ddns.net':9794
- 'cl###cmsv2.xyz':80
- http://www.cl###cmsv2.xyz/w83h/?cD#################################################################################
- DNS ASK em######nglatakva.ddns.net
- DNS ASK cl###cmsv2.xyz
- DNS ASK jd##.net
- '%TEMP%\wwigrjchqaquoowjokay fb.exe'
- '%WINDIR%\syswow64\wlanext.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\Wwigrjchqaquoowjokay fb.exe"