Техническая информация
- [HKCU\Software\Microsoft\Windows\Currentversion\Run] '{96E5DA79-556D-BCA0-6AC4-4881A7315283}' = '%APPDATA%\Dainr\wowot.exe'
- <SYSTEM32>\sihost.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\taskhostw.exe
- %WINDIR%\explorer.exe
- %WINDIR%\systemapps\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\startmenuexperiencehost.exe
- <SYSTEM32>\runtimebroker.exe
- %WINDIR%\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
- <SYSTEM32>\dllhost.exe
- <SYSTEM32>\securityhealthsystray.exe
- <SYSTEM32>\oobe\useroobebroker.exe
- %WINDIR%\syswow64\cmd.exe
- iexplore.exe
- firefox.exe
- %APPDATA%\dainr\wowot.exe
- %TEMP%\tmp9583d8b5.bat
- '50.##3.102.57':13182
- '20#.#11.121.140':10974
- '68.##2.252.216':18464
- '67.##9.77.255':14418
- '20#.#23.27.12':20729
- '68.##5.44.96':28486
- '31.##0.213.189':24000
- '89.##3.95.50':24000
- '19#.#18.99.180':18068
- '19#.#4.127.98':25549
- '11#.#02.139.102':11232
- '85.#1.57.48':29433
- '%APPDATA%\dainr\wowot.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\tmp9583d8b5.bat" (со скрытым окном)