Техническая информация
- <SYSTEM32>\tasks\flowsshnet32
- %WINDIR%\tasks\securityserver.job
- <SYSTEM32>\tasks\securityserver
- %WINDIR%\syswow64\ftp.exe
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\bd1d697b
- %TEMP%\bd9dd3f0
- %APPDATA%\cicpfips32\bit9be1.tmp
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
- %TEMP%\blxvxdxgasa
- %APPDATA%\cicpfips32\bit9be1.tmp
- %APPDATA%\cicpfips32\bit9be1.tmp в %APPDATA%\cicpfips32\flowsshnet32.exe
- 're######bilitybridge.com':80
- http://re######bilitybridge.com/8BvxwQdec3/index.php
- DNS ASK re######bilitybridge.com
- '%WINDIR%\syswow64\ftp.exe'
- '%WINDIR%\syswow64\explorer.exe'