Техническая информация
- <SYSTEM32>\tasks\explorer
- <SYSTEM32>\tasks\spoolsv
- <SYSTEM32>\tasks\<Имя файла>
- <SYSTEM32>\tasks\<Имя файла>n
- <SYSTEM32>\tasks\spoolsvs
- <SYSTEM32>\tasks\wudfhostw
- <SYSTEM32>\tasks\taskhostt
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\iexplorei
- <SYSTEM32>\tasks\winlogonw
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\mdm
- <SYSTEM32>\tasks\servicess
- <SYSTEM32>\tasks\mdmm
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\wudfhost
- <SYSTEM32>\tasks\firefoxf
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\csrssc
- <SYSTEM32>\tasks\audiodg
- <SYSTEM32>\tasks\audiodga
- <SYSTEM32>\tasks\system
- <SYSTEM32>\tasks\systems
- <SYSTEM32>\tasks\explorere
- <SYSTEM32>\tasks\services
- <SYSTEM32>\tasks\taskhost
- mdm.exe
- %ProgramFiles(x86)%\steam\config\config.vdf
- %ProgramFiles(x86)%\steam\config\dialogconfig.vdf
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\13.jpg
- %HOMEPATH%\desktop\168.jpg
- %HOMEPATH%\desktop\2.jpg
- %HOMEPATH%\desktop\parnas_01.jpg
- <Текущая директория>\explorer.exe
- %ProgramFiles%\msimn\9db6e019d4f04e
- %ProgramFiles(x86)%\winamp\lang\mdm.exe
- %ProgramFiles(x86)%\winamp\lang\559fba5f8e4410
- %ProgramFiles%\fsqh\firefox.exe
- %ProgramFiles%\fsqh\0fc223bdacedc3
- %ProgramFiles(x86)%\windows defender\en-us\taskhost.exe
- %ProgramFiles(x86)%\windows defender\en-us\b75386f1303e64
- %TEMP%\my3qmhts8w
- %TEMP%\g3ugukev2d
- %TEMP%\cmnhxvvtnr
- %TEMP%\uytlmmvgbh
- %TEMP%\qsemeqtrzp
- %TEMP%\xorzkepwj8
- %TEMP%\zvhkb1xw76
- %TEMP%\ontbvkkorg
- %TEMP%\d6xqczvldk
- %TEMP%\dirsuuzyjf
- %TEMP%\3t2uuwkxb9
- %TEMP%\ykdagfehuh
- %TEMP%\kmal4f5kra
- %TEMP%\ulflmuecfp
- %TEMP%\pijew2e0lp
- %ProgramFiles%\msimn\iexplore.exe
- %TEMP%\lepm4lynj2
- %ProgramFiles%\fspex\7a0fd90576e088
- %ProgramFiles(x86)%\windows photo viewer\en-us\480b7989c529f6
- <Текущая директория>\7a0fd90576e088
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\system.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\27d1bcfc3c54e0
- %ProgramFiles%\fameh32\audiodg.exe
- %ProgramFiles%\fameh32\42af1c969fbb7b
- <Текущая директория>\csrss.exe
- <Текущая директория>\886983d96e3d3e
- C:\far2\pluginsdk\headers.pas\firefox.exe
- C:\far2\pluginsdk\headers.pas\0fc223bdacedc3
- %ProgramFiles(x86)%\windows photo viewer\en-us\wudfhost.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe
- C:\totalcmd\language\480b7989c529f6
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\559fba5f8e4410
- C:\totalcmd\language\<Имя файла>.exe
- C:\totalcmd\language\1eb4404e8dc556
- C:\far2\plugins\farcmds\spoolsv.exe
- C:\far2\plugins\farcmds\f3b6ecef712a24
- C:\far2\addons\colors\custom_highlighting\services.exe
- C:\far2\addons\colors\custom_highlighting\c5b4cb5e9653cc
- <Текущая директория>\winlogon.exe
- <Текущая директория>\cc11b995f2a76d
- C:\totalcmd\language\wudfhost.exe
- %ProgramFiles%\fspex\explorer.exe
- %TEMP%\bjfbpnpcow
- %TEMP%\my3qmhts8w
- %TEMP%\pijew2e0lp
- %TEMP%\ulflmuecfp
- %TEMP%\kmal4f5kra
- %TEMP%\ykdagfehuh
- %TEMP%\3t2uuwkxb9
- %TEMP%\dirsuuzyjf
- %TEMP%\qsemeqtrzp
- %TEMP%\d6xqczvldk
- %TEMP%\zvhkb1xw76
- %TEMP%\xorzkepwj8
- %TEMP%\uytlmmvgbh
- %TEMP%\lepm4lynj2
- %TEMP%\cmnhxvvtnr
- %TEMP%\g3ugukev2d
- %TEMP%\ontbvkkorg
- %TEMP%\bjfbpnpcow
- '23.##7.193.58':80
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- http://23.##7.193.58/trackwordpressdleCentral.php?CG#############################################################################################################################################...
- http://23.##7.193.58/trackwordpressdleCentral.php?6v#############################################################################################################################################...
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- DNS ASK ip##fo.io
- DNS ASK ap#.##legram.org
- 'C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe'
- 'C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe' ' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 7 /tr "'<Текущая директория>\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "servicess" /sc MINUTE /mo 7 /tr "'C:\Far2\Addons\Colors\Custom_Highlighting\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 5 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 9 /tr "'<Текущая директория>\winlogon.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'<Текущая директория>\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 14 /tr "'<Текущая директория>\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 13 /tr "'C:\totalcmd\LANGUAGE\WUDFHost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHost" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 9 /tr "'C:\totalcmd\LANGUAGE\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 14 /tr "'%ProgramFiles%\fspex\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "servicess" /sc MINUTE /mo 6 /tr "'C:\Far2\Addons\Colors\Custom_Highlighting\services.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "services" /sc ONLOGON /tr "'C:\Far2\Addons\Colors\Custom_Highlighting\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc ONLOGON /tr "'%ProgramFiles%\fspex\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles%\msimn\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 9 /tr "'%ProgramFiles%\msimn\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 6 /tr "'%ProgramFiles(x86)%\Winamp\Lang\mdm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdm" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Winamp\Lang\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 7 /tr "'%ProgramFiles(x86)%\Winamp\Lang\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 13 /tr "'%ProgramFiles%\fsqh\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'%ProgramFiles%\fsqh\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 9 /tr "'%ProgramFiles%\fsqh\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 9 /tr "'%ProgramFiles(x86)%\Windows Defender\en-US\taskhost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 10 /tr "'%ProgramFiles%\fspex\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 13 /tr "'%ProgramFiles%\msimn\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsvs" /sc MINUTE /mo 10 /tr "'C:\Far2\Plugins\FarCmds\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsv" /sc ONLOGON /tr "'C:\Far2\Plugins\FarCmds\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsvs" /sc MINUTE /mo 7 /tr "'C:\Far2\Plugins\FarCmds\spoolsv.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 11 /tr "'<Текущая директория>\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SystemS" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\System.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "System" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SystemS" /sc MINUTE /mo 10 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 12 /tr "'%ProgramFiles%\FAMEH32\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc ONLOGON /tr "'%ProgramFiles%\FAMEH32\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 11 /tr "'%ProgramFiles%\FAMEH32\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrssc" /sc MINUTE /mo 7 /tr "'<Текущая директория>\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc ONLOGON /tr "'<Текущая директория>\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrssc" /sc MINUTE /mo 8 /tr "'<Текущая директория>\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc ONLOGON /tr "'<Текущая директория>\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 11 /tr "'C:\Far2\PluginSDK\Headers.pas\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 7 /tr "'C:\Far2\PluginSDK\Headers.pas\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 10 /tr "'%ProgramFiles(x86)%\Windows Photo Viewer\en-US\WUDFHost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHost" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Windows Photo Viewer\en-US\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 8 /tr "'%ProgramFiles(x86)%\Windows Photo Viewer\en-US\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 10 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdm" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 10 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<Имя файла>n" /sc MINUTE /mo 14 /tr "'C:\totalcmd\LANGUAGE\<Имя файла>.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<Имя файла>" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<Имя файла>n" /sc MINUTE /mo 13 /tr "'C:\totalcmd\LANGUAGE\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'C:\Far2\PluginSDK\Headers.pas\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhost" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Windows Defender\en-US\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 7 /tr "'%ProgramFiles(x86)%\Windows Defender\en-US\taskhost.exe'" /rl HIGHEST /f