Техническая информация
- <SYSTEM32>\tasks\dshca
- [HKLM\System\CurrentControlSet\Services\PROCEXP152] 'ImagePath' = '<DRIVERS>\PROCEXP152.SYS'
- 'PROCEXP152' <DRIVERS>\PROCEXP152.SYS
- Компонент восстановления системы (SR)
- <Текущая директория>\nwatjv4c.exe
- <Текущая директория>\bad_4e33a7a22a9dfa14.txt
- <Текущая директория>\elog_4e33a7a22a9dfa14.txt
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage\permanent\chrome\idb\#nobad_readme#.rtf
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\#nobad_readme#.rtf
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\#nobad_readme#.rtf
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\default\moz-extension+++d39c0de0-06d0-4e01-844c-98b240b2f278^usercontextid=4294967295\idb\#nobad_readme#.rtf
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\#nobad_readme#.rtf
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\default\moz-extension+++db487e04-ae57-4773-9556-37dac4cedf3c^usercontextid=4294967295\idb\#nobad_readme#.rtf
- %TEMP%\seze1lej64.exe
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\#nobad_readme#.rtf
- %LOCALAPPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\offlinecache\#nobad_readme#.rtf
- <Текущая директория>\ftq35g6y.bat
- <Текущая директория>\seze1lej.exe
- %APPDATA%\nbzvywnz.vbs
- %APPDATA%\o4gngjkv.bat
- %APPDATA%\ritrzpbe.bmp
- <Текущая директория>\log.txt
- <Текущая директория>\all_dmp.fldp
- %LOCALAPPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\offlinecache\#nobad_readme#.rtf
- <DRIVERS>\procexp152.sys
- <DRIVERS>\procexp152.sys
- %TEMP%\seze1lej64.exe
- %APPDATA%\nbzvywnz.vbs
- <SYSTEM32>\tasks\dshca
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].0yoljndo-ayvhfpsp.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].tt6lv1wp-mics5vkn.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\history.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].nkpb56ve-474lg6vr.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].yhol0ith-sprsrwjk.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\openpgp.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].egjkgyqv-ybbjs9b4.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\places.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].1ycxedbd-pr7wrh5f.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].hwvxkivj-g2qbjbz1.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\default\moz-extension+++db487e04-ae57-4773-9556-37dac4cedf3c^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql... в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\default\moz-extension+++db487e04-ae57-4773-9556-37dac4cedf3c^usercontextid=4294967295\idb\[inkognitoman@tutamail.com].sbqjtoj...
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\places.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].mpajvwmj-7u8cpevx.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].wds3gslb-ygtupnsk.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].diegbfes-q4jr4ryt.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\enigmail.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].x4pfbrvl-8bcw1eph.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\global-messages-db.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].9sdmzfgv-el2koznu.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\webappsstore.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].8jlwbdtu-4hrubhs9.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\3561288849sdhlie.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].27wejwqw-jk01eknq.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\favicons.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].1sslq6zz-2v2kcnjd.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\webappsstore.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].mumjdxiw-iany0uqx.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\formhistory.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].j7yehfhp-vbdblp8e.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].mpx4rnxw-on9awe4s.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\permissions.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].4tyud2sx-kzxyakpc.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\abook.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].tzyx4mib-pzzydeq3.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\content-prefs.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].k2nalmpv-deofbqug.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\cookies.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].9gndgwmk-upo0mgpl.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].m7wvl9a0-nmifizha.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\default\moz-extension+++d39c0de0-06d0-4e01-844c-98b240b2f278^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.s... в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\default\moz-extension+++d39c0de0-06d0-4e01-844c-98b240b2f278^usercontextid=4294967295\idb\[inkognitoman@tutamail.com].cc2sq...
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].wivlzwth-rlksx1dd.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].ecol7dng-e8ttqkk6.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\blist.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].4un9kutl-8wjbrmuu.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].mwizjdtg-rzwvxbxh.nobad
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\permissions.sqlite в %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\[inkognitoman@tutamail.com].5pzf4e0y-e5c3jntj.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\2918063365piupsah.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].nkbi11nk-pvis7e1k.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\cookies.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].htilquyt-jjlaknsg.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\formhistory.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].zgcsstfo-mbfjwyn0.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\[inkognitoman@tutamail.com].frvc90yr-lf5yjkst.nobad
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\favicons.sqlite в %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\[inkognitoman@tutamail.com].rpgpzvwl-zvgfadzx.nobad
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\cookies.sqlite в %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\[inkognitoman@tutamail.com].osksfb57-e84cmck2.nobad
- %LOCALAPPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\offlinecache\index.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\places.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\openpgp.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\history.sqlite
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\default\moz-extension+++db487e04-ae57-4773-9556-37dac4cedf3c^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql...
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\webappsstore.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\formhistory.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\cookies.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\formhistory.sqlite
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\2918063365piupsah.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\permissions.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\blist.sqlite
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\default\moz-extension+++d39c0de0-06d0-4e01-844c-98b240b2f278^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.s...
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\cookies.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\content-prefs.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\abook.sqlite
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\permissions.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite
- %LOCALAPPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\offlinecache\index.sqlite
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\places.sqlite
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
- %TEMP%\seze1lej64.exe
- '<LOCALNET>.10.10':445
- '<LOCALNET>.10.88':445
- '<LOCALNET>.10.85':139
- '<LOCALNET>.10.89':445
- '<LOCALNET>.10.87':139
- '<LOCALNET>.10.90':445
- '<LOCALNET>.10.86':139
- '<LOCALNET>.10.91':445
- '<LOCALNET>.10.88':139
- '<LOCALNET>.10.92':445
- '<LOCALNET>.10.89':139
- '<LOCALNET>.10.95':445
- '<LOCALNET>.10.90':139
- '<LOCALNET>.10.93':445
- '<LOCALNET>.10.99':139
- '<LOCALNET>.10.91':139
- '<LOCALNET>.10.92':139
- '<LOCALNET>.10.96':445
- '<LOCALNET>.10.95':139
- '<LOCALNET>.10.97':445
- '<LOCALNET>.10.93':139
- '<LOCALNET>.10.98':445
- '<LOCALNET>.10.94':139
- '<LOCALNET>.10.99':445
- '<LOCALNET>.10.96':139
- '<LOCALNET>.10.100':445
- '<LOCALNET>.10.97':139
- '<LOCALNET>.10.101':445
- '<LOCALNET>.10.98':139
- '<LOCALNET>.10.86':445
- '<LOCALNET>.10.84':139
- '<LOCALNET>.10.94':445
- '<LOCALNET>.10.102':445
- '<LOCALNET>.10.82':139
- '<LOCALNET>.10.72':445
- '<LOCALNET>.10.67':139
- '<LOCALNET>.10.73':445
- '<LOCALNET>.10.70':139
- '<LOCALNET>.10.74':445
- '<LOCALNET>.10.71':139
- '<LOCALNET>.10.75':445
- '<LOCALNET>.10.72':139
- '<LOCALNET>.10.76':445
- '<LOCALNET>.10.73':139
- '<LOCALNET>.10.77':445
- '<LOCALNET>.10.75':139
- '<LOCALNET>.10.80':445
- '<LOCALNET>.10.74':139
- '<LOCALNET>.10.78':445
- '<LOCALNET>.10.76':139
- '<LOCALNET>.10.79':445
- '<LOCALNET>.10.77':139
- '<LOCALNET>.10.81':445
- '<LOCALNET>.10.80':139
- '<LOCALNET>.10.82':445
- '<LOCALNET>.10.78':139
- '<LOCALNET>.10.83':445
- '<LOCALNET>.10.79':139
- '<LOCALNET>.10.84':445
- '<LOCALNET>.10.81':139
- '<LOCALNET>.10.85':445
- '<LOCALNET>.10.87':445
- '<LOCALNET>.10.68':139
- '<LOCALNET>.10.83':139
- '<LOCALNET>.10.45':445
- '<LOCALNET>.10.103':445
- '<LOCALNET>.10.121':445
- '<LOCALNET>.10.122':445
- '<LOCALNET>.10.119':139
- '<LOCALNET>.10.120':139
- '<LOCALNET>.10.123':445
- '<LOCALNET>.10.124':445
- '<LOCALNET>.10.121':139
- '<LOCALNET>.10.125':445
- '<LOCALNET>.10.122':139
- '<LOCALNET>.10.126':445
- '<LOCALNET>.10.124':139
- '<LOCALNET>.10.127':445
- '<LOCALNET>.10.123':139
- '<LOCALNET>.10.129':445
- '<LOCALNET>.10.100':139
- '<LOCALNET>.10.125':139
- '<LOCALNET>.10.126':139
- '<LOCALNET>.10.130':445
- '<LOCALNET>.10.127':139
- '<LOCALNET>.10.131':445
- '<LOCALNET>.10.129':139
- '<LOCALNET>.10.132':445
- '<LOCALNET>.10.128':139
- '<LOCALNET>.10.133':445
- '<LOCALNET>.10.130':139
- '<LOCALNET>.10.134':445
- '<LOCALNET>.10.131':139
- '<LOCALNET>.10.135':445
- '<LOCALNET>.10.117':139
- '<LOCALNET>.10.120':445
- '<LOCALNET>.10.118':139
- '<LOCALNET>.10.116':139
- '<LOCALNET>.10.119':445
- '<LOCALNET>.10.104':445
- '<LOCALNET>.10.105':445
- '<LOCALNET>.10.102':139
- '<LOCALNET>.10.106':445
- '<LOCALNET>.10.103':139
- '<LOCALNET>.10.104':139
- '<LOCALNET>.10.108':445
- '<LOCALNET>.10.107':445
- '<LOCALNET>.10.105':139
- '<LOCALNET>.10.109':445
- '<LOCALNET>.10.106':139
- '<LOCALNET>.10.110':445
- '<LOCALNET>.10.108':139
- '<LOCALNET>.10.69':139
- '<LOCALNET>.10.111':445
- '<LOCALNET>.10.71':445
- '<LOCALNET>.10.112':445
- '<LOCALNET>.10.113':445
- '<LOCALNET>.10.111':139
- '<LOCALNET>.10.114':445
- '<LOCALNET>.10.110':139
- '<LOCALNET>.10.115':445
- '<LOCALNET>.10.114':139
- '<LOCALNET>.10.116':445
- '<LOCALNET>.10.112':139
- '<LOCALNET>.10.117':445
- '<LOCALNET>.10.113':139
- '<LOCALNET>.10.118':445
- '<LOCALNET>.10.115':139
- '<LOCALNET>.10.107':139
- '<LOCALNET>.10.101':139
- '<LOCALNET>.10.109':139
- '<LOCALNET>.10.70':445
- '<LOCALNET>.10.67':445
- '<LOCALNET>.10.68':445
- '<LOCALNET>.10.21':445
- '<LOCALNET>.10.18':139
- '<LOCALNET>.10.22':445
- '<LOCALNET>.10.20':139
- '<LOCALNET>.10.23':445
- '<LOCALNET>.10.19':139
- '<LOCALNET>.10.25':445
- '<LOCALNET>.10.21':139
- '<LOCALNET>.10.24':445
- '<LOCALNET>.10.22':139
- '<LOCALNET>.10.26':445
- '<LOCALNET>.10.23':139
- '<LOCALNET>.10.27':445
- '<LOCALNET>.10.25':139
- '<LOCALNET>.10.28':445
- '<LOCALNET>.10.24':139
- '<LOCALNET>.10.29':445
- '<LOCALNET>.10.26':139
- '<LOCALNET>.10.30':445
- '<LOCALNET>.10.27':139
- '<LOCALNET>.10.28':139
- '<LOCALNET>.10.32':445
- '<LOCALNET>.10.31':445
- '<LOCALNET>.10.29':139
- '<LOCALNET>.10.33':445
- '<LOCALNET>.10.30':139
- '<LOCALNET>.10.37':445
- '<LOCALNET>.10.19':445
- '<LOCALNET>.10.13':139
- '<LOCALNET>.10.16':139
- '<LOCALNET>.10.17':139
- '<LOCALNET>.10.18':445
- '<LOCALNET>.10.2':139
- '<LOCALNET>.10.9':445
- '<LOCALNET>.10.6':445
- '<LOCALNET>.10.10':139
- '<LOCALNET>.10.6':139
- '<LOCALNET>.10.11':445
- '<LOCALNET>.10.3':139
- '<LOCALNET>.10.1':445
- '<LOCALNET>.10.9':139
- '<LOCALNET>.10.2':445
- '<LOCALNET>.10.5':445
- '<LOCALNET>.10.11':139
- '<LOCALNET>.10.4':445
- '<LOCALNET>.10.5':139
- '<LOCALNET>.10.32':139
- '<LOCALNET>.10.132':139
- '<LOCALNET>.10.8':445
- '<LOCALNET>.10.1':139
- '<LOCALNET>.10.14':445
- '<LOCALNET>.10.4':139
- '<LOCALNET>.10.12':445
- '<LOCALNET>.10.8':139
- '<LOCALNET>.10.14':139
- '<LOCALNET>.10.15':445
- '<LOCALNET>.10.13':445
- '<LOCALNET>.10.7':139
- '<LOCALNET>.10.17':445
- '<LOCALNET>.10.12':139
- '<LOCALNET>.10.16':445
- '<LOCALNET>.10.15':139
- '<LOCALNET>.10.3':445
- '<LOCALNET>.10.7':445
- '<LOCALNET>.10.128':445
- '<LOCALNET>.10.34':445
- '<LOCALNET>.10.38':445
- '<LOCALNET>.10.54':139
- '<LOCALNET>.10.55':445
- '<LOCALNET>.10.52':139
- '<LOCALNET>.10.57':445
- '<LOCALNET>.10.53':139
- '<LOCALNET>.10.58':445
- '<LOCALNET>.10.56':139
- '<LOCALNET>.10.59':445
- '<LOCALNET>.10.55':139
- '<LOCALNET>.10.60':445
- '<LOCALNET>.10.57':139
- '<LOCALNET>.10.61':445
- '<LOCALNET>.10.20':445
- '<LOCALNET>.10.58':139
- '<LOCALNET>.10.59':139
- '<LOCALNET>.10.63':445
- '<LOCALNET>.10.60':139
- '<LOCALNET>.10.64':445
- '<LOCALNET>.10.61':139
- '<LOCALNET>.10.65':445
- '<LOCALNET>.10.62':139
- '<LOCALNET>.10.63':139
- '<LOCALNET>.10.64':139
- '<LOCALNET>.10.65':139
- '<LOCALNET>.10.66':445
- '<LOCALNET>.10.66':139
- '<LOCALNET>.10.69':445
- '<LOCALNET>.10.53':445
- '<LOCALNET>.10.62':445
- '<LOCALNET>.10.56':445
- '<LOCALNET>.10.51':139
- '<LOCALNET>.10.50':139
- '<LOCALNET>.10.54':445
- '<LOCALNET>.10.37':139
- '<LOCALNET>.10.40':445
- '<LOCALNET>.10.34':139
- '<LOCALNET>.10.39':445
- '<LOCALNET>.10.35':139
- '<LOCALNET>.10.41':445
- '<LOCALNET>.10.40':139
- '<LOCALNET>.10.39':139
- '<LOCALNET>.10.44':445
- '<LOCALNET>.10.42':445
- '<LOCALNET>.10.38':139
- '<LOCALNET>.10.43':445
- '<LOCALNET>.10.31':139
- '<LOCALNET>.10.41':139
- '<LOCALNET>.10.35':445
- '<LOCALNET>.10.44':139
- '<LOCALNET>.10.42':139
- '<LOCALNET>.10.45':139
- '<LOCALNET>.10.48':445
- '<LOCALNET>.10.43':139
- '<LOCALNET>.10.47':445
- '<LOCALNET>.10.49':445
- '<LOCALNET>.10.46':139
- '<LOCALNET>.10.50':445
- '<LOCALNET>.10.49':139
- '<LOCALNET>.10.51':445
- '<LOCALNET>.10.48':139
- '<LOCALNET>.10.52':445
- '<LOCALNET>.10.33':139
- '<LOCALNET>.10.47':139
- '<LOCALNET>.10.46':445
- '<LOCALNET>.10.136':445
- DNS ASK no###.#ygoodsday.org
- '<Текущая директория>\seze1lej.exe' -accepteula -c 55C -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c D08 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c C7C -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c C80 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c C94 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c 558 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "content-prefs.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c DA0 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c Run -y -p extract -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c DA4 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c DCC -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "formhistory.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "places.sqlite" -nobanner
- '%TEMP%\seze1lej64.exe' -accepteula "permissions.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c C98 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c C70 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "favicons.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c DA8 -y -p 1944 -nobanner
- '<Текущая директория>\nwatjv4c.exe' -n
- '<Текущая директория>\seze1lej.exe' -accepteula -c 554 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c 564 -y -p 1944 -nobanner
- '%WINDIR%\syswow64\wscript.exe' //B //Nologo "%APPDATA%\NbZVyWNz.vbs"
- '<Текущая директория>\seze1lej.exe' -accepteula "cookies.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "storage.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c 320 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "webappsstore.sqlite" -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula -c 4A4 -y -p 1944 -nobanner
- '<Текущая директория>\seze1lej.exe' -accepteula "permissions.sqlite" -nobanner
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\formhistory.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C schtasks /Run /I /tn DSHCA' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\storage.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\favicons.sqlite""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\o4Gngjkv.bat"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\cookies.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C reg add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "%APPDATA%\RitRZPbE.bmp" /f & reg add "HKCU\Control Panel\Desktop" /v WallpaperStyle /t REG_SZ /d "0" /f & reg add "HKCU\Contro...' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\webappsstore.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\permissions.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C wscript //B //Nologo "%APPDATA%\NbZVyWNz.vbs"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C schtasks /Create /tn DSHCA /tr "%APPDATA%\o4Gngjkv.bat" /sc minute /mo 5 /RL HIGHEST /F' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\content-prefs.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\places.sqlite""' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C copy /V /Y "<Полный путь к файлу>" "<Текущая директория>\NWAtJv4c.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C copy /V /Y "<Полный путь к файлу>" "<Текущая директория>\NWAtJv4c.exe"
- '<SYSTEM32>\taskeng.exe' {0CF384E4-0624-4B50-8ED8-4634ADD922C7} S-1-5-21-1238866942-1249195528-555854008-1000:jbahluk\user:Interactive:[1]
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\favicons.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "content-prefs.sqlite" -nobanner
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\favicons.sqlite"
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\o4Gngjkv.bat"
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\formhistory.sqlite""
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "favicons.sqlite" -nobanner
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\formhistory.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "permissions.sqlite" -nobanner
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\formhistory.sqlite"
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\storage.sqlite""
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\storage.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\storage.sqlite"
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "storage.sqlite" -nobanner
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\cookies.sqlite""
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\cookies.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\cookies.sqlite"
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "cookies.sqlite" -nobanner
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\favicons.sqlite""
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\content-prefs.sqlite"
- '%WINDIR%\syswow64\schtasks.exe' /Run /I /tn DSHCA
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\content-prefs.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\cmd.exe' /C schtasks /Run /I /tn DSHCA
- '%WINDIR%\syswow64\cmd.exe' /C wscript //B //Nologo "%APPDATA%\NbZVyWNz.vbs"
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "%APPDATA%\RitRZPbE.bmp" /f
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\permissions.sqlite""
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Control Panel\Desktop" /v WallpaperStyle /t REG_SZ /d "0" /f
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\permissions.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Control Panel\Desktop" /v TileWallpaper /t REG_SZ /d "0" /f
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\webappsstore.sqlite""
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\permissions.sqlite"
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "formhistory.sqlite" -nobanner
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\webappsstore.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\cmd.exe' /C schtasks /Create /tn DSHCA /tr "%APPDATA%\o4Gngjkv.bat" /sc minute /mo 5 /RL HIGHEST /F
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "webappsstore.sqlite" -nobanner
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\places.sqlite""
- '%WINDIR%\syswow64\schtasks.exe' /Create /tn DSHCA /tr "%APPDATA%\o4Gngjkv.bat" /sc minute /mo 5 /RL HIGHEST /F
- '%WINDIR%\syswow64\cacls.exe' "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\places.sqlite" /E /G user:F /C
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\places.sqlite"
- '%WINDIR%\syswow64\cmd.exe' /c ""<Текущая директория>\fTq35G6y.bat" "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\content-prefs.sqlite""
- '%WINDIR%\syswow64\cmd.exe' /c seZE1lEj.exe -accepteula "places.sqlite" -nobanner
- '%WINDIR%\syswow64\cmd.exe' /C reg add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "%APPDATA%\RitRZPbE.bmp" /f & reg add "HKCU\Control Panel\Desktop" /v WallpaperStyle /t REG_SZ /d "0" /f & reg add "HKCU\Contro...
- '%WINDIR%\syswow64\takeown.exe' /F "%APPDATA%\Mozilla\Firefox\Profiles\yfwt7ezn.default-release-1\webappsstore.sqlite"
- '<SYSTEM32>\schtasks.exe' /Delete /TN DSHCA /F