Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 35cf8773a85755e7
- <SYSTEM32>\tasks\rovwer.exe
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- %APPDATA%\ftistue
- %APPDATA%\dftwihh
- %TEMP%\88fd.exe
- %TEMP%\b667dbdcd8\rovwer.exe
- %APPDATA%\ftistue
- %APPDATA%\dftwihh
- 'o3####s3sn6xou.com':80
- 'th#####ncondition.com':443
- '77.##.134.249':80
- '17#.#13.115.201':80
- http://77.##.134.249/vr/movie.exe
- http://o3####s3sn6xou.com/
- http://17#.#13.115.201/3g4mn5s/index.php
- 'th#####ncondition.com':443
- DNS ASK o3####s3sn6xou.com
- DNS ASK th#####ncondition.com
- '%TEMP%\88fd.exe'
- '%TEMP%\b667dbdcd8\rovwer.exe'
- '%TEMP%\b667dbdcd8\rovwer.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN rovwer.exe /TR "%TEMP%\b667dbdcd8\rovwer.exe" /F' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN rovwer.exe /TR "%TEMP%\b667dbdcd8\rovwer.exe" /F