Техническая информация
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- iexplore.exe
- chrome.exe
- firefox.exe
- %TEMP%\unist10988.txt
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'www.lo###neinc.com':80
- 'ww#.####rn.inetplugin.com':80
- '<IP-адрес в локальной сети>':445
- www.lo###neinc.com/wp-content/uploads/2012/07/2-f4b0c9d9fbf3df23229e1987d05440fc/A/cntx/notify.php
- ww#.####rn.inetplugin.com/js/ism.jsp
- DNS ASK www.lo###neinc.com
- DNS ASK ww#.####rn.inetplugin.com