Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 1bee838b966e9545
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %TEMP%\ixp000.tmp\v9894058.exe
- %TEMP%\ixp000.tmp\c7077154.exe
- %TEMP%\ixp001.tmp\a8176171.exe
- %TEMP%\ixp001.tmp\b7163418.exe
- %APPDATA%\evhtswc
- %TEMP%\c59f.exe
- %APPDATA%\evhtswc
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- '77.#1.68.29':80
- '77.#1.68.78':80
- http://77.#1.68.78/lend/rqrba.exe
- http://77.#1.68.29/fks/
- '%TEMP%\ixp000.tmp\v9894058.exe'
- '%TEMP%\ixp001.tmp\a8176171.exe'
- '%TEMP%\c59f.exe'
- '%APPDATA%\evhtswc'
- '%TEMP%\ixp000.tmp\v9894058.exe' ' (со скрытым окном)
- '%TEMP%\ixp001.tmp\a8176171.exe' ' (со скрытым окном)
- '%APPDATA%\evhtswc' ' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe'
- '<SYSTEM32>\taskeng.exe' {73A41E9B-FE2A-4E9B-8814-A679BE4B0498} S-1-5-21-3150914307-1777937420-491476919-1000:ipdbbnkspnr\user:Interactive:[1]