Техническая информация
- '<SYSTEM32>\attrib.exe' +h "%TEMP%\\System.db"
- '<SYSTEM32>\ntvdm.exe' -f -i1
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- %TEMP%\System.db
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9
- %TEMP%\System.db
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- '20#.#6.232.182':80
- 'wp#d':80
- 20#.#6.232.182/pki/crl/products/CSPCA.crl
- wp#d/wpad.dat
- DNS ASK crl.microsoft.com
- DNS ASK wp#d
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-cfc.d00.380001'