Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent a412532656aaf31e
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- toolspub2.exe
- %APPDATA%\ewucwvf
- %TEMP%\a035.exe
- %TEMP%\a61f.exe
- %TEMP%\installsetup5.exe
- %TEMP%\toolspub2.exe
- %TEMP%\31839b57a4f11171d6abc8bbc4451ee4.exe
- %TEMP%\121b.exe
- %TEMP%\broom.exe
- %APPDATA%\ewucwvf
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %TEMP%\toolspub2.exe
- '5.##.92.190':80
- '5.##.65.80':80
- '19#.#9.94.72':80
- '19#.#9.94.11':80
- http://5.##.65.80/newrock.exe
- http://19#.#9.94.72/1.exe
- http://19#.#9.94.11/
- http://5.##.92.190/fks/index.php
- '%TEMP%\a035.exe'
- '%TEMP%\a61f.exe'
- '%TEMP%\installsetup5.exe'
- '%TEMP%\toolspub2.exe'
- '%TEMP%\31839b57a4f11171d6abc8bbc4451ee4.exe'
- '%TEMP%\121b.exe'
- '%TEMP%\broom.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\A9FA.bat" "' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\A9FA.bat" "