Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /t /im <Имя файла>.exe
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\109be4.tmp
- %TEMP%\10a01a.tmp
- %TEMP%\10ad88.tmp
- %TEMP%\10b085.tmp
- %APPDATA%\lark\config.dat
- %TEMP%\dellark.bat
- %TEMP%\109be4.tmp
- %TEMP%\10a01a.tmp
- %TEMP%\10ad88.tmp
- %TEMP%\10b085.tmp
- http://on#####.#nfile.inspurcloud.cn/Blacklist.txt
- DNS ASK on#####.#nfile.inspurcloud.cn
- DNS ASK cl####.###-cn-beijing.aliyuncs.com
- DNS ASK m.###eyz.com
- ClassName: '18467-41' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\delLark.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\delLark.bat