Техническая информация
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\af61.tmp
- %TEMP%\b07b.tmp
- %TEMP%\b240.tmp
- %TEMP%\f21e.tmp
- %TEMP%\f2b7.tmp
- %TEMP%\f316.tmp
- %TEMP%\f374.tmp
- %TEMP%\1016.tmp
- %TEMP%\1084.tmp
- %TEMP%\1150.tmp
- %TEMP%\af61.tmp
- %TEMP%\b07b.tmp
- %TEMP%\b240.tmp
- %TEMP%\f2b7.tmp
- %TEMP%\f316.tmp
- %TEMP%\f374.tmp
- %TEMP%\1016.tmp
- %TEMP%\1084.tmp
- %TEMP%\1150.tmp
- 'fe##era.com':80
- http://fe##era.com/task.php?id####################################################################
- http://fe##era.com/grabber.pcp
- DNS ASK fe##era.com
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs
- '%WINDIR%\syswow64\explorer.exe'