Техническая информация
- %WINDIR%\tasks\gqyjef.job
- <SYSTEM32>\tasks\gqyjef
- %TEMP%\ixp000.tmp\assume.a3x
- %TEMP%\ixp000.tmp\autoit3.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\56ff0e98ed\gqyjef.exe
- %TEMP%\ixp000.tmp\autoit3.exe
- %TEMP%\ixp000.tmp\assume.a3x
- DNS ASK cp############ASXbNXfANQs.cptbsYhoxaajwMASXbNXfANQs
- DNS ASK microsoft.com
- '%TEMP%\ixp000.tmp\autoit3.exe' Assume.a3x
- '%TEMP%\56ff0e98ed\gqyjef.exe'
- '%TEMP%\ixp000.tmp\autoit3.exe' Assume.a3x (со скрытым окном)
- '%TEMP%\56ff0e98ed\gqyjef.exe' (со скрытым окном)