Техническая информация
- '<SYSTEM32>\cmd.exe' /C net view \\CRNJEUFU
- '<SYSTEM32>\net.exe' view \\CRNJEUFU
- '<SYSTEM32>\cmd.exe' /C net view
- '<SYSTEM32>\net.exe' view
- %HOMEPATH%\Desktop\!---HOW-TO-RETURN-YOUR-FILES---!.jpg
- %HOMEPATH%\My Documents\esa.fvr
- %HOMEPATH%\My Documents\!---HOW-TO-RETURN-YOUR-FILES---!.jpg
- %APPDATA%\Microsoft\Protect\CREDHIST
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\11d6346265a461c8e380647a1003d5e6_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %HOMEPATH%\Desktop\esa.fvr
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\11d6346265a461c8e380647a1003d5e6_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db.t3km11
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db.t3km11
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db.t3km11