Техническая информация
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\wlanext.exe
- gkvlc.exe
- firefox.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\nsr8096.tmp
- %TEMP%\gzvlobsyjjr.l
- %TEMP%\htujbhttw.eyi
- %TEMP%\gkvlc.exe
- %TEMP%\3_45586py
- %LOCALAPPDATA%\microsoft\vault\userprofileroaming\latest.dat
- 'so###ape.org':80
- 'la####icargo.com':80
- http://www.so###ape.org/qsni/?T6#####################################################################################################################
- DNS ASK st####weiden.click
- DNS ASK de####urveys.com
- DNS ASK pg###aining.com
- DNS ASK da##ar.net
- DNS ASK no###aks.com
- DNS ASK lo##w.space
- DNS ASK pa###iky.site
- DNS ASK co####nnect.online
- DNS ASK so###ape.org
- DNS ASK th#####nerudraksha.com
- DNS ASK we###lech.shop
- DNS ASK la####icargo.com
- '%TEMP%\gkvlc.exe' %TEMP%\htujbhttw.eyi
- '%TEMP%\gkvlc.exe'
- '%WINDIR%\syswow64\wlanext.exe'
- '%ProgramFiles%\mozilla firefox\firefox.exe'