Техническая информация
- '%PROGRAM_FILES%\DIFX\lsas.exe'
- 'C:\rar.txt' e -y -p520xinyu c:\jian.jpg "%PROGRAM_FILES%\DIFX\"
- '<SYSTEM32>\wscript.exe' "%PROGRAM_FILES%\DIFX\vbs2.vbs"
- '<SYSTEM32>\wbem\mofcomp.exe' -N:root\cimv2 <SYSTEM32>\wbem\asecimv2.mof
- '<SYSTEM32>\wscript.exe' "%PROGRAM_FILES%\DIFX\vbs1.vbs"
- %PROGRAM_FILES%\DIFX\lsas.exe
- %PROGRAM_FILES%\DIFX\My1234.txt
- %TEMP%\tmp1.tmp
- <SYSTEM32>\wbem\asecimv2.mof
- %PROGRAM_FILES%\DIFX\vbs2.vbs
- C:\rar.txt
- C:\jian.jpg
- %PROGRAM_FILES%\DIFX\vbs1.vbs
- %PROGRAM_FILES%\DIFX\my.txt
- C:\jian.jpg
- %PROGRAM_FILES%\DIFX\vbs1.vbs
- %PROGRAM_FILES%\DIFX\vbs2.vbs
- %TEMP%\tmp1.tmp
- <SYSTEM32>\wbem\asecimv2.mof
- C:\rar.txt
- 'no##.3322.org':8088
- DNS ASK no##.3322.org