Technical Information
- <SYSTEM32>\dllcache\iexplore.exe with <SYSTEM32>\dllcache\iexplore.exe.new
- <SYSTEM32>\taskkill.exe /im iexplore.exe /f
- <SYSTEM32>\taskkill.exe /im chrome.exe /f
- <SYSTEM32>\taskkill.exe /im browser.exe /f
- <SYSTEM32>\taskkill.exe /im firefox.exe /f
- chrome.exe
- firefox.exe
- iexplore.exe
- %PROGRAM_FILES%\iinhbaeevbtkvhbbrnkfhrwuvxeqogrdtmuekmtloanryeemlaisfhyeiblczfqfbgraogudkjexrqpr.zip
- from <SYSTEM32>\dllcache\iexplore.exe.new to <SYSTEM32>\dllcache\iexplore.exe
- from %PROGRAM_FILES%\Internet Explorer\iexplore.exe.new to %PROGRAM_FILES%\Internet Explorer\iexplore.exe
- 'si###ati.com':80
- si###ati.com/ext.zip
- si###ati.com/gorev.php?ok##
- si###ati.com/hosts.txt
- si###ati.com/id.txt?0
- DNS ASK si###ati.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''