Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\ .lnk
- '%TEMP%\Kaspersky.exe'
- '<SYSTEM32>\net1.exe' stop MpsSvc
- '<SYSTEM32>\net.exe' stop MpsSvc
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\549b9b645cadfe6bb4bc69cf363c354c_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %TEMP%\da.doc
- %TEMP%\ico.ico
- %TEMP%\Kaspersky.exe
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\549b9b645cadfe6bb4bc69cf363c354c_23ef5514-3059-436f-a4a7-4cefaab20eb1
- 'up####.ns01.info':8080
- '16#.#20.246.117':8080
- DNS ASK up####.ns01.info
- ClassName: 'WordPadClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''