Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\surmit.vbs
- Системный антивирус (Защитник Windows)
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- firefox.exe
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %TEMP%\aut2bc3.tmp
- %TEMP%\charley
- %LOCALAPPDATA%\emboweling\surmit.exe
- %TEMP%\aut36ef.tmp
- %TEMP%\aut2bc3.tmp
- %TEMP%\aut36ef.tmp
- 'ch####p.dyndns.org':80
- 're####freegeoip.org':443
- 'ap#.##legram.org':443
- 'ma##.####arsshippingintl.com':587
- 're####freegeoip.org':443
- 'ap#.##legram.org':443
- 'ma##.####arsshippingintl.com':587
- DNS ASK ch####p.dyndns.org
- DNS ASK re####freegeoip.org
- DNS ASK ap#.##legram.org
- DNS ASK ma##.####arsshippingintl.com
- '%LOCALAPPDATA%\emboweling\surmit.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'