Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'VMwares' = '%PROGRAM_FILES%\PrinC\spooles.exe'
- '%PROGRAM_FILES%\PrinC\spooles.exe'
- 'C:\InstallWD.exe'
- %PROGRAM_FILES%\PrinC\PrintC.txt
- %PROGRAM_FILES%\PrinC\PrintB.txt
- %PROGRAM_FILES%\PrinC\PrintA.txt
- C:\Pass.txt
- C:\InstallWD.exe
- C:\InstallWD.exe в %PROGRAM_FILES%\PrinC\spooles.exe
- 'ko####.ctlctl.com':3000
- 'ko####.ctlctl.com':800
- 'ko####.ctlctl.com':200
- DNS ASK ko####.ctlctl.com