Техническая информация
- '%TEMP%\MalwareScan.exe' silent
- '%TEMP%\preinstall.exe' silent
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\dumprep.exe' 2868 -dm 7 7 %TEMP%\WER3cfe.dir00\MalwareScan.exe.hdmp 16325836412027516
- '<SYSTEM32>\dumprep.exe' 2868 -dm 7 7 %TEMP%\WER3cfe.dir00\MalwareScan.exe.mdmp 16325836412027496
- %TEMP%\preinstall.exe
- %TEMP%\Pattern.dat
- %TEMP%\WER3cfe.dir00\MalwareScan.exe.hdmp
- %TEMP%\WER3cfe.dir00\MalwareScan.exe.mdmp
- %TEMP%\MalwareScan.exe
- %TEMP%\HelperModule.dll
- %TEMP%\FP1.tmp
- %TEMP%\loadDll.exe
- %TEMP%\hmkernel.sys
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\FP1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sver_new[1].htm
- 'li#####ate.alyac.co.kr':80
- li#####ate.alyac.co.kr/etc/analysis/scanner/sver_new.htm
- DNS ASK li#####ate.alyac.co.kr