Техническая информация
- '%PROGRAM_FILES%\mirdlq\神舞五季登陆器.exe'
- '<SYSTEM32>\attrib.exe' +r +a +s +h <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' -r -a -s -h <DRIVERS>\etc\hosts
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc /T /C /P everyone:N
- '<SYSTEM32>\cacls.exe' * /g everyone:f
- '<SYSTEM32>\wscript.exe' "%PROGRAM_FILES%\mirdlq\yx.vbe"
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc /T /C /P everyone:F
- '<SYSTEM32>\attrib.exe' -r -a -s -h *
- %PROGRAM_FILES%\mirdlq\gh999t.txt
- <DRIVERS>\etc\ggg.a
- %PROGRAM_FILES%\mirdlq\神舞五季登陆器.exe
- %PROGRAM_FILES%\mirdlq\ggg.a
- %PROGRAM_FILES%\mirdlq\yx.vbe
- <DRIVERS>\etc\hosts
- %PROGRAM_FILES%\mirdlq\yx.vbe
- %PROGRAM_FILES%\mirdlq\gh999t.txt
- <DRIVERS>\etc\ggg.a
- %PROGRAM_FILES%\mirdlq\gh999t.txt в %PROGRAM_FILES%\mirdlq\ggg.a
- 'gh#.#ygxs.com':888
- 'localhost':1036
- DNS ASK gh#.#ygxs.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'