Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\skype.lnk
- '%WINDIR%\syswow64\taskkill.exe' /im "Teoxcocihawoliz"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "wscript.exe"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "cscript.exe"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "macromedia.exe"
- '%WINDIR%\syswow64\taskkill.exe' /im "shell.exe"
- '%WINDIR%\syswow64\taskkill.exe' /im Shell.exe
- '%WINDIR%\syswow64\taskkill.exe' /im macromedia.exe
- %APPDATA%\windowshelp\coinutil.dll
- %APPDATA%\windowshelp\shel\shell.exe_part3
- %APPDATA%\windowshelp\shel\shell.exe_part30
- %APPDATA%\windowshelp\shel\shell.exe_part31
- %APPDATA%\windowshelp\shel\shell.exe_part32
- %APPDATA%\windowshelp\shel\shell.exe_part33
- %APPDATA%\windowshelp\shel\shell.exe_part34
- %APPDATA%\windowshelp\shel\shell.exe_part35
- %APPDATA%\windowshelp\shel\shell.exe_part45
- %APPDATA%\windowshelp\shel\shell.exe_part29
- %APPDATA%\windowshelp\shel\shell.exe_part28
- %APPDATA%\windowshelp\shel\shell.exe_part39
- %APPDATA%\windowshelp\shel\shell.exe_part4
- %APPDATA%\windowshelp\shel\shell.exe_part40
- %APPDATA%\windowshelp\shel\shell.exe_part41
- %APPDATA%\windowshelp\shel\shell.exe_part42
- %APPDATA%\windowshelp\shel\shell.exe_part43
- %APPDATA%\windowshelp\shel\shell.exe_part44
- %APPDATA%\windowshelp\shel\shell.exe_part36
- %APPDATA%\windowshelp\shel\shell.exe_part38
- %APPDATA%\windowshelp\puts.vbs
- %APPDATA%\windowshelp\shel\shell.exe_part37
- %APPDATA%\windowshelp\shel\shell.exe_part17
- %APPDATA%\windowshelp\shel\shell.exe_part1
- %APPDATA%\windowshelp\shel\shell.exe_part10
- %APPDATA%\windowshelp\shel\shell.exe_part11
- %APPDATA%\windowshelp\shel\shell.exe_part12
- %APPDATA%\windowshelp\shel\shell.exe_part13
- %APPDATA%\windowshelp\shel\shell.exe_part14
- %APPDATA%\windowshelp\shel\shell.exe_part15
- %APPDATA%\windowshelp\shel\shell.exe_part25
- %APPDATA%\windowshelp\shel\shell.exe_part27
- %APPDATA%\windowshelp\shel\shell.exe_part26
- %APPDATA%\windowshelp\shel\shell.exe_part19
- %APPDATA%\windowshelp\shel\shell.exe_part2
- %APPDATA%\windowshelp\shel\shell.exe_part20
- %APPDATA%\windowshelp\shel\shell.exe_part21
- %APPDATA%\windowshelp\shel\shell.exe_part22
- %APPDATA%\windowshelp\shel\shell.exe_part23
- %APPDATA%\windowshelp\shel\shell.exe_part24
- %APPDATA%\windowshelp\shel\shell.exe_part16
- %APPDATA%\windowshelp\shel\shell.exe_part18
- %APPDATA%\windowshelp\shel\compile.bat
- %APPDATA%\windowshelp\shel\shell.exe_part46
- %APPDATA%\windowshelp\shel\shell.exe_part5
- %APPDATA%\windowshelp\shel\shell.exe_part7
- %APPDATA%\windowshelp\shel\shell.exe_part70
- %APPDATA%\windowshelp\shel\shell.exe_part71
- %APPDATA%\windowshelp\shel\shell.exe_part72
- %APPDATA%\windowshelp\shel\shell.exe_part73
- %APPDATA%\windowshelp\shel\shell.exe_part74
- %APPDATA%\windowshelp\shel\shell.exe_part75
- %APPDATA%\windowshelp\shel\shell.exe_part68
- %APPDATA%\windowshelp\shel\shell.exe_part69
- %APPDATA%\windowshelp\shel\shell.exe_part76
- %APPDATA%\windowshelp\shel\shell.exe_part79
- %APPDATA%\windowshelp\shel\shell.exe_part8
- %APPDATA%\windowshelp\shel\shell.exe_part80
- %APPDATA%\windowshelp\shel\shell.exe_part81
- %APPDATA%\windowshelp\shel\shell.exe_part82
- %APPDATA%\windowshelp\shel\shell.exe_part9
- %APPDATA%\windowshelp\usft_ext.dll
- %APPDATA%\windowshelp\shel\shell.exe_part77
- %APPDATA%\windowshelp\shel\shell.exe_part78
- %APPDATA%\windowshelp\shel\shell.exe_part48
- %APPDATA%\windowshelp\shel\shell.exe_part47
- %APPDATA%\windowshelp\shel\shell.exe_part65
- %APPDATA%\windowshelp\shel\shell.exe_part50
- %APPDATA%\windowshelp\shel\shell.exe_part51
- %APPDATA%\windowshelp\shel\shell.exe_part52
- %APPDATA%\windowshelp\shel\shell.exe_part53
- %APPDATA%\windowshelp\shel\shell.exe_part54
- %APPDATA%\windowshelp\shel\shell.exe_part55
- %APPDATA%\windowshelp\shel\shell.exe_part66
- %APPDATA%\windowshelp\shel\shell.exe_part49
- %APPDATA%\windowshelp\shel\shell.exe_part67
- %APPDATA%\windowshelp\shel\shell.exe_part56
- %APPDATA%\windowshelp\shel\shell.exe_part6
- %APPDATA%\windowshelp\shel\shell.exe_part60
- %APPDATA%\windowshelp\shel\shell.exe_part61
- %APPDATA%\windowshelp\shel\shell.exe_part62
- %APPDATA%\windowshelp\shel\shell.exe_part63
- %APPDATA%\windowshelp\shel\shell.exe_part64
- %APPDATA%\windowshelp\shel\shell.exe_part57
- %APPDATA%\windowshelp\shel\shell.exe_part58
- %APPDATA%\windowshelp\shel\shell.exe_part59
- %APPDATA%\windowshelp\phatk.ptx
- %APPDATA%\windowshelp\phatk.cl
- %APPDATA%\windowshelp\openssl.dll
- %APPDATA%\windowshelp\macro\macromedia.exe_part29
- %APPDATA%\windowshelp\macro\macromedia.exe_part3
- %APPDATA%\windowshelp\macro\macromedia.exe_part30
- %APPDATA%\windowshelp\macro\macromedia.exe_part31
- %APPDATA%\windowshelp\macro\macromedia.exe_part32
- %APPDATA%\windowshelp\macro\macromedia.exe_part33
- %APPDATA%\windowshelp\macro\macromedia.exe_part34
- %APPDATA%\windowshelp\macro\macromedia.exe_part27
- %APPDATA%\windowshelp\macro\macromedia.exe_part44
- %APPDATA%\windowshelp\macro\macromedia.exe_part26
- %APPDATA%\windowshelp\macro\macromedia.exe_part38
- %APPDATA%\windowshelp\macro\macromedia.exe_part39
- %APPDATA%\windowshelp\macro\macromedia.exe_part4
- %APPDATA%\windowshelp\macro\macromedia.exe_part40
- %APPDATA%\windowshelp\macro\macromedia.exe_part41
- %APPDATA%\windowshelp\macro\macromedia.exe_part42
- %APPDATA%\windowshelp\macro\macromedia.exe_part43
- %APPDATA%\windowshelp\macro\macromedia.exe_part36
- %APPDATA%\windowshelp\macro\macromedia.exe_part35
- %APPDATA%\windowshelp\macro\macromedia.exe_part37
- %APPDATA%\windowshelp\macro\macromedia.exe_part24
- %APPDATA%\windowshelp\macro\macromedia.exe_part17
- %APPDATA%\windowshelp\macro\compile.bat
- %APPDATA%\windowshelp\macro\macromedia.exe_part1
- %APPDATA%\windowshelp\macro\macromedia.exe_part10
- %APPDATA%\windowshelp\macro\macromedia.exe_part11
- %APPDATA%\windowshelp\macro\macromedia.exe_part12
- %APPDATA%\windowshelp\macro\macromedia.exe_part13
- %APPDATA%\windowshelp\macro\macromedia.exe_part14
- %APPDATA%\windowshelp\macro\macromedia.exe_part25
- %APPDATA%\windowshelp\macro\macromedia.exe_part45
- %APPDATA%\windowshelp\killer.bat
- %APPDATA%\windowshelp\macro\macromedia.exe_part18
- %APPDATA%\windowshelp\macro\macromedia.exe_part19
- %APPDATA%\windowshelp\macro\macromedia.exe_part2
- %APPDATA%\windowshelp\macro\macromedia.exe_part20
- %APPDATA%\windowshelp\macro\macromedia.exe_part21
- %APPDATA%\windowshelp\macro\macromedia.exe_part22
- %APPDATA%\windowshelp\macro\macromedia.exe_part23
- %APPDATA%\windowshelp\macro\macromedia.exe_part16
- %APPDATA%\windowshelp\macro\macromedia.exe_part15
- %APPDATA%\windowshelp\macro\macromedia.exe_part28
- %APPDATA%\windowshelp\macro\macromedia.exe_part46
- %APPDATA%\windowshelp\macro\macromedia.exe_part69
- %APPDATA%\windowshelp\macro\macromedia.exe_part70
- %APPDATA%\windowshelp\macro\macromedia.exe_part71
- %APPDATA%\windowshelp\macro\macromedia.exe_part72
- %APPDATA%\windowshelp\macro\macromedia.exe_part73
- %APPDATA%\windowshelp\macro\macromedia.exe_part74
- %APPDATA%\windowshelp\macro\macromedia.exe_part75
- %APPDATA%\windowshelp\macro\macromedia.exe_part68
- %APPDATA%\windowshelp\macro\macromedia.exe_part66
- %APPDATA%\windowshelp\macro\macromedia.exe_part7
- %APPDATA%\windowshelp\macro\macromedia.exe_part76
- %APPDATA%\windowshelp\macro\macromedia.exe_part8
- %APPDATA%\windowshelp\macro\macromedia.exe_part80
- %APPDATA%\windowshelp\macro\macromedia.exe_part81
- %APPDATA%\windowshelp\macro\macromedia.exe_part82
- %APPDATA%\windowshelp\macro\macromedia.exe_part9
- %APPDATA%\windowshelp\miner.dll
- %APPDATA%\windowshelp\macro\macromedia.exe_part77
- %APPDATA%\windowshelp\macro\macromedia.exe_part78
- %APPDATA%\windowshelp\macro\macromedia.exe_part79
- %APPDATA%\windowshelp\macro\macromedia.exe_part67
- %APPDATA%\windowshelp\macro\macromedia.exe_part65
- %APPDATA%\windowshelp\macro\macromedia.exe_part47
- %APPDATA%\windowshelp\macro\macromedia.exe_part49
- %APPDATA%\windowshelp\macro\macromedia.exe_part5
- %APPDATA%\windowshelp\macro\macromedia.exe_part50
- %APPDATA%\windowshelp\macro\macromedia.exe_part51
- %APPDATA%\windowshelp\macro\macromedia.exe_part52
- %APPDATA%\windowshelp\macro\macromedia.exe_part53
- %APPDATA%\windowshelp\macro\macromedia.exe_part54
- %APPDATA%\windowshelp\macro\macromedia.exe_part55
- %APPDATA%\windowshelp\macro\macromedia.exe_part48
- %APPDATA%\windowshelp\macro\macromedia.exe_part56
- %APPDATA%\windowshelp\macro\macromedia.exe_part58
- %APPDATA%\windowshelp\macro\macromedia.exe_part59
- %APPDATA%\windowshelp\macro\macromedia.exe_part6
- %APPDATA%\windowshelp\macro\macromedia.exe_part60
- %APPDATA%\windowshelp\macro\macromedia.exe_part61
- %APPDATA%\windowshelp\macro\macromedia.exe_part62
- %APPDATA%\windowshelp\macro\macromedia.exe_part63
- %APPDATA%\windowshelp\macro\macromedia.exe_part64
- %APPDATA%\windowshelp\macro\macromedia.exe_part57
- %APPDATA%\windowshelp\usft_ext.exe.vbs
- nul
- %APPDATA%\windowshelp\shel\shell.exe_part1 в %APPDATA%\windowshelp\shel\shell.exe
- %APPDATA%\windowshelp\shel\shell.exe в %APPDATA%\windowshelp\shell.exe
- %APPDATA%\windowshelp\macro\macromedia.exe_part1 в %APPDATA%\windowshelp\macro\macromedia.exe
- %APPDATA%\windowshelp\macro\macromedia.exe в %APPDATA%\windowshelp\macromedia.exe
- DNS ASK st#####.btcguild.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%APPDATA%\windowshelp\macromedia.exe' -a sha256 -o stratum+tcp://stratum.btcguild.com:3333 -u zeusandthehazard_1 -p 123 -g no -t 1
- '%APPDATA%\windowshelp\shell.exe' -a sha256 -o stratum+tcp://stratum.btcguild.com:3333 -u zeusandthehazard_1 -p 123 -t 0 -I -5
- '%WINDIR%\syswow64\wscript.exe' puts.vbs
- '%WINDIR%\syswow64\cmd.exe' /c killer.bat (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 5 127.0.0.1
- '%WINDIR%\syswow64\cscript.exe' usft_ext.exe.vbs
- '%WINDIR%\syswow64\taskkill.exe' /im Shell.exe (со скрытым окном)
- '%WINDIR%\syswow64\taskkill.exe' /im macromedia.exe (со скрытым окном)
- '%APPDATA%\windowshelp\macromedia.exe' -a sha256 -o stratum+tcp://stratum.btcguild.com:3333 -u zeusandthehazard_1 -p 123 -g no -t 1 (со скрытым окном)
- '%APPDATA%\windowshelp\shell.exe' -a sha256 -o stratum+tcp://stratum.btcguild.com:3333 -u zeusandthehazard_1 -p 123 -t 0 -I -5 (со скрытым окном)