Technical Information
- <SYSTEM32>\svchost.exe
- %APPDATA%\System.Data.SQLite.xml
- %APPDATA%\System.Data.SQLite.dll
- %APPDATA%\SQLite.Interop.dll
- %APPDATA%\Uninstall.ini
- %APPDATA%\Uninstall.exe
- %APPDATA%\System Disk.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\Mine.exe
- %TEMP%\Отстук.vbs
- %TEMP%\FSVHZ.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\dimaro.vbs
- %TEMP%\crted.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'ip###ger.com':443
- DNS ASK ip###ger.com
- '%TEMP%\Mine.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\dimaro.vbs"
- '%TEMP%\FSVHZ.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\Отстук.vbs"
- '<SYSTEM32>\svchost.exe'