Техническая информация
- <SYSTEM32>\tasks\toolsaachieveafeaturesaoptimizea
- C:\users\public\music\yab0jo\6bfzmwkwd.exe
- C:\users\public\music\yab0jo\6bfzmwkwd.dat
- C:\users\public\music\yab0jo\edge.xml
- C:\users\public\music\yab0jo\edge.jpg
- %TEMP%\_ir_tu2_temp_0\irimg1.jpg
- %TEMP%\_ir_tu2_temp_0\irimg2.jpg
- %TEMP%\_ir_tu2_temp_0\irimg3.jpg
- %TEMP%\_ir_tu2_temp_0\irimg4.jpg
- %TEMP%\_ir_tu2_temp_0\_tuprojdt.dat
- %TEMP%\xshell 6 update log.txt
- C:\users\public\music\yab0jo\8ag109.exe
- C:\users\public\music\yab0jo\8ag109.dat
- C:\xxxx.ini
- '20#.#38.221.81':7800
- 'as##tw.com':7014
- '20#.#38.221.81':7000
- http://20#.##8.221.81:7800/L-8 via 20#.#38.221.81
- http://20#.##8.221.81:7800/1 via 20#.#38.221.81
- http://20#.##8.221.81:7800/2 via 20#.#38.221.81
- http://20#.##8.221.81:7800/3 via 20#.#38.221.81
- http://20#.##8.221.81:7800/4 via 20#.#38.221.81
- '20#.#38.221.81':7000
- DNS ASK as##tw.com
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- 'C:\users\public\music\yab0jo\6bfzmwkwd.exe'
- 'C:\users\public\music\yab0jo\6bfzmwkwd.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini