Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\47TTN.exe
- '%APPDATA%\WinRAR\QN43CK2z8DNAJx.exe'
- '%HOMEPATH%\Start Menu\Programs\Startup\47TTN.exe'
- '<LS_APPDATA>\C78HD.exe'
- '%APPDATA%\WinRAR\QN43dfg2z8DNAJx.exe' -p5bLmTtXQN43CK2z8DNAJxC
- '%HOMEPATH%\Start Menu\Programs\Startup\47TTN.exe' (загружен из сети Интернет)
- '<SYSTEM32>\wscript.exe' "<LS_APPDATA>\PuiREbOYVFUk.vbs"
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wscript.exe' "%APPDATA%\WinRAR\43CK2z8DNAJxCqXwI.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\WinRAR\K2z8DNAJxC.bat" "
- %APPDATA%\WinRAR\43CK2z8DNAJxCqXwI.vbs
- %APPDATA%\WinRAR\QN43CK2z8DNAJx.exe
- <LS_APPDATA>\PuiREbOYVFUk.vbs
- <LS_APPDATA>\C78HD.exe
- %APPDATA%\WinRAR\K2z8DNAJxC.bat
- %APPDATA%\WinRAR\QN43dfg2z8DNAJx.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <LS_APPDATA>\C78HD.exe
- 'no####ot.ssmukir.ru':80
- 'localhost':1037
- no####ot.ssmukir.ru/WinRAR.exe
- DNS ASK no####ot.ssmukir.ru
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''