Техническая информация
- %TEMP%\nswd479.tmp
- %TEMP%\nsmd48a.tmp\nsexec.dll
- %TEMP%\nsmd48a.tmp\settings.reg
- %PROGRAMDATA%\corel\bin\540227267\540111142\x-force.bin
- %TEMP%\nsmd48a.tmp\nsexec.dll
- %TEMP%\nsmd48a.tmp\settings.reg
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="all" remoteip=95.141.193.133' (со скрытым окном)
- '%WINDIR%\syswow64\route.exe' delete 95.141.193.133' (со скрытым окном)
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns' (со скрытым окном)
- '%WINDIR%\syswow64\regedit.exe' /s "%TEMP%\nsmD48A.tmp\Settings.reg"' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="all" remoteip=95.141.193.133
- '%WINDIR%\syswow64\route.exe' delete 95.141.193.133
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns
- '%WINDIR%\syswow64\regedit.exe' /s "%TEMP%\nsmD48A.tmp\Settings.reg"