Техническая информация
- '<SYSTEM32>\net.exe' stop srumon
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<Имя файла>.exe.log
- %WINDIR%\appcompat\programs\hgztqmof.3df
- %WINDIR%\appcompat\programs\52k0qz0i.xlr
- %WINDIR%\appcompat\programs\kz1pf1i1.4gl
- %WINDIR%\appcompat\programs\amcache.hve в %WINDIR%\appcompat\programs\hgztqmof.3df
- %WINDIR%\appcompat\programs\amcache.hve.log1 в %WINDIR%\appcompat\programs\52k0qz0i.xlr
- %WINDIR%\appcompat\programs\amcache.hve.log2 в %WINDIR%\appcompat\programs\kz1pf1i1.4gl
- <SYSTEM32>\sru\srudb.dat в <SYSTEM32>\sru\am4vq1gm.psp
- DNS ASK di##ord.com
- '<SYSTEM32>\net1.exe' stop srumon