Техническая информация
- <SYSTEM32>\tasks\microsoftedgeupdatetaskmachineus
- %HOMEPATH%\pictures\desktop.ini:coll9
- %HOMEPATH%\pictures\desktop.ini:arqwc
- %HOMEPATH%\pictures\desktop.ini:mosz1
- 'me############led-directly-vid.trycloudflare.com':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'me############led-directly-vid.trycloudflare.com':443
- DNS ASK me############led-directly-vid.trycloudflare.com
- DNS ASK pk#.goog
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Pictures\desktop.ini:colL9" //b //e:::vbscript /adr/adradre //e:vbscript //b //e:vbscript /adr/ico/kye
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Pictures\desktop.ini:colL9" //b //e:::vbscript /adr/adradre //e:vbscript //b //e:vbscript /adr/ico/kye (со скрытым окном)