Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\suite-i19.lnk
- %LOCALAPPDATA%\lustgoddess\icon.ico
- %LOCALAPPDATA%\lustgoddess\lg.ps1
- %HOMEPATH%\desktop\lust goddess.lnk
- DNS ASK i.###timg.cc
- ClassName: '#32770' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "%LOCALAPPDATA%\LustGoddess\\lg.ps1"
- '%WINDIR%\syswow64\attrib.exe' +h %APPDATA%\trade