Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %TEMP%\ixp000.tmp\rk0mi07.exe
- %TEMP%\ixp000.tmp\13lp213.exe
- %TEMP%\ixp001.tmp\11eo0582.exe
- %TEMP%\ixp001.tmp\12md724.exe
- %TEMP%\ixp001.tmp\12md724.exe
- %TEMP%\ixp001.tmp\11eo0582.exe
- %TEMP%\ixp000.tmp\13lp213.exe
- %TEMP%\ixp000.tmp\rk0mi07.exe
- '5.##.92.43':80
- 'he###teeakl.pw':80
- http://he###teeakl.pw/api
- DNS ASK he###teeakl.pw
- '%TEMP%\ixp000.tmp\rk0mi07.exe'
- '%TEMP%\ixp001.tmp\11eo0582.exe'
- '%TEMP%\ixp001.tmp\12md724.exe'
- '%TEMP%\ixp000.tmp\13lp213.exe'
- '%TEMP%\ixp000.tmp\rk0mi07.exe' ' (со скрытым окном)
- '%TEMP%\ixp001.tmp\11eo0582.exe' ' (со скрытым окном)
- '%TEMP%\ixp001.tmp\12md724.exe' ' (со скрытым окном)
- '%TEMP%\ixp000.tmp\13lp213.exe' ' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'