Техническая информация
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\parnas_01.jpeg
- %HOMEPATH%\desktop\sdszfo.docx
- C:\kms\# how to decrypt files.txt
- %HOMEPATH%\contacts\# how to decrypt files.txt
- C:\kms\kms_vl_all_aio_debug.log
- %HOMEPATH%\contacts\user.contact
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\parnas_01.jpeg
- 'ip##fo.io':443
- 'ip##fo.io':443
- DNS ASK ip##fo.io
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C sc config eventlog start=disabled
- '<SYSTEM32>\sc.exe' config eventlog start=disabled
- '<SYSTEM32>\cmd.exe' /C REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" / v Start / t REG_DWORD / d 4 / f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" / v Start / t REG_DWORD / d 4 / f
- '<SYSTEM32>\tasklist.exe' /V /FO CSV