Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 78964a219cc632ca
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %APPDATA%\teadaut
- %APPDATA%\hijgerc
- %TEMP%\84c8.exe
- %APPDATA%\teadaut
- %APPDATA%\hijgerc
- 'ho#####hwugh2gie.com':80
- '45.##.157.136':80
- 't.#e':443
- 'st####ommunity.com':443
- 'tr##sfer.sh':443
- 'ti##url.com':443
- 'gi##ub.com':443
- 'microsoft.com':80
- http://45.##.157.136/shared/Ruzvelt.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://ho#####hwugh2gie.com/
- 't.#e':443
- 'st####ommunity.com':443
- 'tr##sfer.sh':443
- 'ti##url.com':443
- 'gi##ub.com':443
- DNS ASK ho#####hwugh2gie.com
- DNS ASK t.#e
- DNS ASK st####ommunity.com
- DNS ASK tr##sfer.sh
- DNS ASK ti##url.com
- DNS ASK gi##ub.com
- DNS ASK microsoft.com
- '%TEMP%\84c8.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'