Техническая информация
- [HKCU\Software\Microsoft\Windows\Currentversion\Run] 'profiles.exe' = '%APPDATA%\Thunderbird\Profiles\gbmwccb6.default-release\storage\permanent\chrome\idb\profiles.exe'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\storage\permanent\chrome\idb\profiles.exe
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\storage\permanent\chrome\idb\sessioncheckpoints.ani
- %TEMP%\updf8554700.bat
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\storage\permanent\chrome\idb\sessioncheckpoints.tmp
- DNS ASK ji#####nbjbejrbr.gdn
- '%APPDATA%\thunderbird\profiles\gbmwccb6.default-release\storage\permanent\chrome\idb\profiles.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\updf8554700.bat" (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs