Technical Information
- <SYSTEM32>\tasks\system\systemcheck
- %ProgramFiles(x86)%\steam\crashhandler.dll
- helper.exe
- %TEMP%\aut4e3e.tmp
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-certs.tmp
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\unverified-microdesc-consensus.tmp
- %APPDATA%\microsoft\windows\tor\tordata\tor.pid
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\state.tmp
- %APPDATA%\microsoft\windows\tor\tordata\torconfig
- %APPDATA%\microsoft\windows\tor\zlib1.dll
- %APPDATA%\microsoft\windows\tor\tor.exe
- %APPDATA%\microsoft\windows\tor\ssleay32.dll
- %APPDATA%\microsoft\windows\tor\libwinpthread-1.dll
- %APPDATA%\microsoft\windows\tor\libssp-0.dll
- %APPDATA%\microsoft\windows\tor\libgmp-10.dll
- %APPDATA%\microsoft\windows\tor\libgcc_s_sjlj-1.dll
- %APPDATA%\microsoft\windows\tor\libevent_extra-2-1-6.dll
- %APPDATA%\microsoft\windows\tor\libevent_core-2-1-6.dll
- %APPDATA%\microsoft\windows\tor\libevent-2-1-6.dll
- %APPDATA%\microsoft\windows\tor\libeay32.dll
- %APPDATA%\microsoft\windows\tor.tmp
- %APPDATA%\microsoft\windows\helper.exe
- %TEMP%\64.exe
- %TEMP%\32.exe
- %TEMP%\systemcheck.xml
- %TEMP%\start2.bat
- %TEMP%\start.bat
- %TEMP%\steam.exe
- %TEMP%\autc1b3.tmp
- %TEMP%\cl_debug_log.txt
- %TEMP%\autc164.tmp
- %TEMP%\cr_debug_log.txt
- %TEMP%\asacpiex.dll
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-microdesc-consensus.tmp
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-microdescs.new
- %TEMP%\aut4e3e.tmp
- %TEMP%\autc164.tmp
- %TEMP%\autc1b3.tmp
- %TEMP%\32.exe
- %TEMP%\64.exe
- %TEMP%\systemcheck.xml
- %TEMP%\cr_debug_log.txt
- %TEMP%\cl_debug_log.txt
- %TEMP%\start2.bat
- %TEMP%\asacpiex.dll
- %APPDATA%\microsoft\windows\tor.tmp
- %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\unverified-microdesc-consensus
- from %ProgramFiles(x86)%\steam\crashhandler.dll to %ProgramFiles(x86)%\steam\steamlibrary.dll
- from %APPDATA%\microsoft\windows\tor\tor.exe to %APPDATA%\microsoft\windows\tor\tor.exe
- from %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\state.tmp to %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\state
- from %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\unverified-microdesc-consensus.tmp to %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\unverified-microdesc-consensus
- from %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-certs.tmp to %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-certs
- from %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-microdesc-consensus.tmp to %APPDATA%\microsoft\windows\tor\tordatasockslistenaddress 127.0.0.1\cached-microdesc-consensus
- %ProgramFiles(x86)%\Steam\crashhandler.dll
- 'ez##at.ru':80
- '18#.#00.86.128':9001
- '21#.#2.199.190':443
- '51.##5.41.65':9001
- '16#.#72.176.167':443
- '37.#53.1.10':9001
- '81.#.14.253':443
- '20#.#.156.142':443
- '96.##3.78.108':443
- '19#.#34.15.56':443
- '92.##2.38.67':443
- '16#.#72.194.53':9001
- '21#.#1.134.123':9001
- '45.#6.33.45':443
- '18#.#20.101.4':30004
- '18#.#29.62.62':9001
- '18#.#6.180.29':443
- '21#.#7.229.2':9001
- '83.##2.99.68':443
- 'microsoft.com':80
- 'localhost':49178
- '31.##5.104.20':443
- 'localhost':9303
- '37.##7.255.35':9090
- '13#.#48.241.5':9001
- 'ip###ger.org':443
- '45.##.108.130':9001
- '14#.#6.14.145':143
- '21#.#7.244.38':443
- '21#.#3.154.33':8443
- '21#.#39.217.18':1337
- '51.##4.96.208':9001
- '18#.#20.101.7':30007
- '19#.#54.164.243':443
- '81.#.16.182':443
- '51.##4.101.242':9001
- 'ez##at.ru':443
- '16#.#72.194.53':9001
- '45.#6.33.45':443
- '18#.#29.62.62':9001
- '96.##3.78.108':443
- '37.#53.1.10':9001
- '18#.#20.101.4':30004
- '18#.#00.86.128':9001
- '20#.#.156.142':443
- '19#.#34.15.56':443
- '45.##.108.130':9001
- '81.#.14.253':443
- '51.##4.96.208':9001
- '21#.#7.229.2':9001
- '18#.#20.101.7':30007
- '21#.#7.244.38':443
- '19#.#54.164.243':443
- '37.##7.255.35':9090
- 'localhost':9303
- '13#.#48.241.5':9001
- '81.#.16.182':443
- DNS ASK ez##at.ru
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- '%TEMP%\cl_debug_log.txt' e -p"JDQJndnqwdnqw2139dn21n3b312idDQDB" "%TEMP%\CR_Debug_Log.txt" -o"%TEMP%\"
- '%TEMP%\steam.exe'
- '%APPDATA%\microsoft\windows\helper.exe' -SystemCheck
- '%APPDATA%\microsoft\windows\helper.exe' -RunSc
- '%APPDATA%\microsoft\windows\helper.exe' e -p"DxSqsNKKOxqPrM4Y3xeK" "%APPDATA%\Microsoft\Windows\Tor.tmp" -o"%APPDATA%\Microsoft\Windows\Tor\"
- '%APPDATA%\microsoft\windows\tor\tor.exe' -f TorConfig
- '%TEMP%\cl_debug_log.txt' e -p"JDQJndnqwdnqw2139dn21n3b312idDQDB" "%TEMP%\CR_Debug_Log.txt" -o"%TEMP%\"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\start.bat' (with hidden window)
- '%APPDATA%\microsoft\windows\helper.exe' -SystemCheck' (with hidden window)
- '%APPDATA%\microsoft\windows\helper.exe' e -p"DxSqsNKKOxqPrM4Y3xeK" "%APPDATA%\Microsoft\Windows\Tor.tmp" -o"%APPDATA%\Microsoft\Windows\Tor\"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\start.bat
- '%WINDIR%\syswow64\schtasks.exe' /Create /XML "SystemCheck.xml" /TN "System\SystemCheck"
- '%WINDIR%\syswow64\cmd.exe' /c title $1G7DVFCaMBctAj9z.exe$
- '<SYSTEM32>\taskeng.exe' {D3EE9C1D-A016-40A2-96C3-50011793045A} S-1-5-21-1960123792-2022915161-3775307078-1001:gheyemls\user:Interactive:[1]