Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %APPDATA%\yu.exe
- %APPDATA%\mainmodule.exe
- %APPDATA%\yu.exe
- '19#.#06.191.160':8673
- 'cd#.##scordapp.com':443
- '19#.#06.191.160':8673
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '%APPDATA%\yu.exe'
- '%APPDATA%\mainmodule.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 0 &Del %APPDATA%\yu.exe
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 0