Техническая информация
- '<SYSTEM32>\cmd.exe' /c %TEMP%\_uninsep.bat
- '<SYSTEM32>\sc.exe' stop aCryptograph stat
- '<SYSTEM32>\sc.exe' config aCryptograph start= disabled
- %TEMP%\_uninsep.bat
- C:\Temp.temp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\LockMainPage[1].txt
- C:\Temp.temp
- 'dl#.#ljtl8.com':80
- 'localhost':1036
- dl#.#ljtl8.com/Files/LockMainPage.txt
- DNS ASK dl#.#ljtl8.com