Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent d81623a4a1c2320c
- <SYSTEM32>\tasks\jiqqx
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %APPDATA%\avrrgfb
- %APPDATA%\uibgcdr
- %TEMP%\57c.exe
- %LOCALAPPDATA%\navjrt\jiqqx.exe
- %APPDATA%\avrrgfb
- %APPDATA%\uibgcdr
- 'ko####olitizm.org':80
- 'gi##ub.com':443
- 'dr##box.com':443
- 'vk.com':80
- 'vk.com':443
- 'cd#####.anonfiles.com':443
- 'tr##sfer.sh':443
- 'th#####nsicinsight.org':443
- 'si##ky.net':443
- '10#.#22.188.59':80
- 'al##is.com':443
- http://vk.com/
- http://10#.#22.188.59/put.exe
- http://ko####olitizm.org/
- 'gi##ub.com':443
- 'dr##box.com':443
- 'vk.com':443
- 'cd#####.anonfiles.com':443
- 'tr##sfer.sh':443
- 'th#####nsicinsight.org':443
- 'si##ky.net':443
- 'al##is.com':443
- DNS ASK ko####olitizm.org
- DNS ASK gi##ub.com
- DNS ASK dr##box.com
- DNS ASK vk.com
- DNS ASK cd#####.anonfiles.com
- DNS ASK tr##sfer.sh
- DNS ASK th#####nsicinsight.org
- DNS ASK si##ky.net
- DNS ASK al##is.com
- '%TEMP%\57c.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'