Техническая информация
- %WINDIR%\Tasks\ms.job
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\efc6.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\38fr.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\38fr.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\1dl3.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\6eif.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\36b1.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<SYSTEM32>\0dde.dll"
- %TEMP%\h8nil4o8\s.exe
- %TEMP%\h8nil4o8\2.dll
- %TEMP%\h8nil4o8\3.dll
- %TEMP%\h8nil4o8\z.lz
- %TEMP%\h8nil4o8\b.dll
- %TEMP%\h8nil4o8\p.dll
- %TEMP%\h8nil4o8\b.dll в <SYSTEM32>\38fr.dll
- %TEMP%\h8nil4o8\2.dll в %WINDIR%\b7fu.bmp
- %TEMP%\h8nil4o8\p.dll в <SYSTEM32>\ef8s.dll