Техническая информация
- '%TEMP%\install.exe' 336265441891899871
- '%TEMP%\install.exe'
- '%TEMP%\spyqhtnndkbueaxnh.exe' xgmsaowzy.bat++install.exe
- '<SYSTEM32>\taskkill.exe' /f /im "praetorian.exe"
- '<SYSTEM32>\chcp.com' 866
- '<SYSTEM32>\cmd.exe' /c xgmsaowzy.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get_download_xml_3[1]
- <DRIVERS>\etc\hоsts
- %TEMP%\xgmsaowzy.bat
- %TEMP%\install.exe
- %TEMP%\spyqhtnndkbueaxnh.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get_download_xml_3[1]
- 'fi##dwn.ru':80
- fi##dwn.ru/get_download_xml_3?id########
- DNS ASK fi##dwn.ru
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'