Техническая информация
- <SYSTEM32>\securityhealthsystray.exe
- %WINDIR%\syswow64\rundll32.exe
- %WINDIR%\explorer.exe
- qwdqqzzebj.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\twyagsvtzc.po
- %TEMP%\qwdqqzzebj.exe
- %TEMP%\0fenjid4
- %LOCALAPPDATA%\microsoft\vault\userprofileroaming\latest.dat
- 'ro###strong.com':80
- http://www.ro###strong.com/nfgh/?4E######################################################################################################################
- DNS ASK ve###verify.com
- DNS ASK do##c.xyz
- DNS ASK ro###strong.com
- '%TEMP%\qwdqqzzebj.exe'
- '%WINDIR%\syswow64\rundll32.exe'
- '%ProgramFiles%\mozilla firefox\firefox.exe'