Техническая информация
- <SYSTEM32>\tasks\system event notification service
- %APPDATA%\retourna.db
- '%WINDIR%\explorer.exe' "%TEMP%\GFB_Service-Agreement_MDB_AF-Jun2020_P HOP DONG TRA SAU.doc"
- %APPDATA%\retourna.db
- %TEMP%\gfb_service-agreement_mdb_af-jun2020_p hop dong tra sau.doc
- %PROGRAMDATA%\mpsvc.dll
- %PROGRAMDATA%\msmpeng.exe
- '%WINDIR%\explorer.exe' "%TEMP%\GFB_Service-Agreement_MDB_AF-Jun2020_P HOP DONG TRA SAU.doc"' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\GFB_Service-Agreement_MDB_AF-Jun2020_P HOP DONG TRA SAU.doc"' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\GFB_Service-Agreement_MDB_AF-Jun2020_P HOP DONG TRA SAU.doc"