Техническая информация
- %TEMP%\conime.exe
- <SYSTEM32>\net1.exe stop "Security Center"
- <SYSTEM32>\net1.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\net1.exe stop System Restore Service
- <SYSTEM32>\net.exe stop "Security Center"
- <SYSTEM32>\net.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\net.exe stop System Restore Service
- 360tray.exe
- ClassName: 'AVP.Product_Notification' WindowName: ''
- %WINDIR%\SVCH.EXE
- %TEMP%\conime.exe
- из <Полный путь к вирусу> в C:\NTDUBECT.EXE
- ClassName: 'Q360SafeMainClass' WindowName: ''