Техническая информация
- '%ALLUSERSPROFILE%\DRM\XXX\.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135652.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135647.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135642.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135707.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135702.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135657.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135637.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135617.jpg
- %ALLUSERSPROFILE%\DRM\XXX\cacybbzcwpxbbxg
- %ALLUSERSPROFILE%\DRM\XXX\.exe
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135632.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135627.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20130913135622.jpg
- 'localhost':12345
- 'localhost':12345