Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /im "Funshion.exe"
- %WINDIR%\funshioninstall_c50677.exe
- %TEMP%\nse52f0.tmp
- %TEMP%\legendlog.ini
- <Текущая директория>\temp\legendlog.ini
- %TEMP%\nsz5f8f.tmp\system.dll
- %TEMP%\nsz5f8f.tmp\findprocdll.dll
- %TEMP%\nsz5f8f.tmp\killprocdll.dll
- %TEMP%\nsz5f8f.tmp\execcmd.dll
- %TEMP%\nsz5f8f.tmp\welcomepage.ini
- %TEMP%\nsz5f8f.tmp\instpath.ini
- %TEMP%\welcomepage.ini
- %TEMP%\instpath.ini
- %TEMP%\blank.bmp
- %TEMP%\welcome.bmp
- %TEMP%\licensecn.bmp
- %TEMP%\licenseen.bmp
- %TEMP%\installpathcn.bmp
- %TEMP%\installpathen.bmp
- %TEMP%\installfilescn3.bmp
- %TEMP%\installfilescn2.bmp
- %TEMP%\installfilesen3.bmp
- %TEMP%\installfilesen2.bmp
- %TEMP%\nsz5f8f.tmp\iospecial.ini
- %TEMP%\nsz5f8f.tmp\modern-wizard.bmp
- %TEMP%\nsz5f8f.tmp\installoptions.dll
- %TEMP%\legendlog.ini в %LOCALAPPDATA%\temp
- '2.#n':80
- http://2.#n/m.exe
- DNS ASK 2.#n
- ClassName: '' WindowName: ''
- '%WINDIR%\funshioninstall_c50677.exe'
- '%WINDIR%\syswow64\cmd.exe' /C taskkill /f /im "Funshion.exe" (со скрытым окном)