Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TaskEng' = '"%APPDATA%\c9734aa3fedb14d8103de1cbf4222482\e67135e840ee9f93a8ed0567562c7cfa\taskeng.exe"'
- %APPDATA%\c9734aa3fedb14d8103de1cbf4222482\e67135e840ee9f93a8ed0567562c7cfa\taskeng.exe
- <SYSTEM32>\attrib.exe %APPDATA%\c9734aa3fedb14d8103de1cbf4222482\e67135e840ee9f93a8ed0567562c7cfa +s +h
- <SYSTEM32>\cmd.exe /c ""%TEMP%\tmp3.tmp.bat""
- <SYSTEM32>\attrib.exe %APPDATA%\c9734aa3fedb14d8103de1cbf4222482\e67135e840ee9f93a8ed0567562c7cfa\taskeng.exe +s +h
- <SYSTEM32>\cmd.exe /c ""%TEMP%\tmp1.tmp.bat""
- <SYSTEM32>\attrib.exe %APPDATA%\c9734aa3fedb14d8103de1cbf4222482 +s +h
- <SYSTEM32>\cmd.exe /c ""%TEMP%\tmp2.tmp.bat""
- %TEMP%\tmp1.tmp.bat
- %TEMP%\tmp2.tmp.bat
- %TEMP%\tmp3.tmp.bat
- %APPDATA%\temp185.ini
- %HOMEPATH%\Cookies\d7a894dsa56.txt
- %TEMP%\tmpA412.temp
- %APPDATA%\c9734aa3fedb14d8103de1cbf4222482\e67135e840ee9f93a8ed0567562c7cfa\taskeng.exe
- %TEMP%\tmp3.tmp.bat
- %TEMP%\tmp2.tmp.bat
- %TEMP%\tmp1.tmp.bat
- 'co#######2aa91641cae.weebly.com':80
- 'my##sh.net':80
- 'wp#d':80
- co#######2aa91641cae.weebly.com/
- my##sh.net/hd.php
- wp#d/wpad.dat
- DNS ASK co#######2aa91641cae.weebly.com
- DNS ASK my##sh.net
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''