Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '<Текущая директория>'
- <Текущая директория>\resolution.ini
- %HOMEPATH%\desktop\vГµ lГўm pk ctc.lnk
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\8qsnnbrb\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\ckqw07u8\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\ma50l122\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\8lpbbhad\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\8qsnnbrb\info_48[1]
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\ckqw07u8\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\ma50l122\bullet[1]
- DNS ASK ap###.ipify.org
- DNS ASK tu#####nhtieungao.net
- DNS ASK ip##.#canhazip.com
- DNS ASK ap#.#pify.org
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath '<Текущая директория>'