Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 1feacdd710bb593c
- %WINDIR%\explorer.exe
- d317.exe
- %APPDATA%\fvwcegu
- %TEMP%\d317.exe
- %TEMP%\d884.bat
- %APPDATA%\fvwcegu
- 'ho####ile-host6.com':80
- '19#.#49.189.91':80
- 'tr##sfer.sh':443
- 're###kt5569.com':80
- 'fi##bin.net':443
- http://re###kt5569.com/downloads/toolspub1.exe
- http://ho####ile-host6.com/
- 'tr##sfer.sh':443
- 'fi##bin.net':443
- DNS ASK ho####ile-host6.com
- DNS ASK tr##sfer.sh
- DNS ASK re###kt5569.com
- DNS ASK fi##bin.net
- '%TEMP%\d317.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\D884.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\D884.bat" "
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\clicker\key" /v primary /t REG_DWORD /d 1