Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /IM explorer.exe -f
- %WINDIR%\explorer.exe
- %WINDIR%\temp\cab8729.tmp
- %WINDIR%\temp\tar872a.tmp
- %WINDIR%\temp\cab8729.tmp
- %WINDIR%\temp\tar872a.tmp
- 'le####ownload.xyz':80
- 'go#####analytics.com':443
- 'microsoft.com':80
- 'oc##.thawte.com':80
- http://le####ownload.xyz/ixset.php?ip########
- http://le####ownload.xyz/ixpkey.php
- http://le####ownload.xyz/ixptexts.php
- http://le####ownload.xyz/setad.php
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://le####ownload.xyz/ixlive.php?ui###
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'go#####analytics.com':443
- DNS ASK ia#.###ysoftware.com
- DNS ASK le####ownload.xyz
- DNS ASK go#####analytics.com
- DNS ASK microsoft.com
- DNS ASK oc##.thawte.com
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\taskmgr.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\taskmgr.exe'
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /IM explorer.exe -f