Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Task Manager.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\autorun.lnk
- %APPDATA%\Task Manager\20180402.jpeg
- %APPDATA%\Task Manager\autorun.vbe
- %APPDATA%\Task Manager\Bookmarks.db
- %APPDATA%\Task Manager\TaskManager.exe
- %APPDATA%\Task Manager\uxtheme.dll
- 'localhost':1037
- 'my###.ftp21.net':130
- DNS ASK my###.ftp21.net
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %APPDATA%\Task Manager\20180402.jpeg
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Task Manager\autorun.vbe"