Техническая информация
- <SYSTEM32>\tasks\deadlines system productivity plans powerful
- C:\users\public\music\t5u4fej\snnmawjbq.exe
- C:\users\public\music\t5u4fej\snnmawjbq.dat
- C:\users\public\music\t5u4fej\edge.xml
- C:\users\public\music\t5u4fej\edge.jpg
- %TEMP%\_ir_tu2_temp_0\_tuprojdt.dat
- %TEMP%\_ir_tu2_temp_0\irimg1.jpg
- %TEMP%\_ir_tu2_temp_0\irimg2.jpg
- %TEMP%\_ir_tu2_temp_0\irimg3.jpg
- %TEMP%\_ir_tu2_temp_0\irimg4.jpg
- %TEMP%\xshell 6 update log.txt
- C:\users\public\music\t5u4fej\44wf3.exe
- C:\users\public\music\t5u4fej\44wf3.dat
- C:\xxxx.ini
- '16#.#97.240.144':7600
- '16#.#97.240.144':7000
- http://16#.###.240.144:7600/y-26 via 16#.#97.240.144
- http://16#.###.240.144:7600/1 via 16#.#97.240.144
- http://16#.###.240.144:7600/2 via 16#.#97.240.144
- http://16#.###.240.144:7600/3 via 16#.#97.240.144
- http://16#.###.240.144:7600/4 via 16#.#97.240.144
- '16#.#97.240.144':7000
- DNS ASK iu##ut.net
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- 'C:\users\public\music\t5u4fej\snnmawjbq.exe'
- 'C:\users\public\music\t5u4fej\snnmawjbq.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini