Техническая информация
- '%TEMP%\mespv.exe' /stext %TEMP%\mespvp.txt
- '%TEMP%\pv.exe' /stext %TEMP%\pvp.txt
- '%TEMP%\mpv.exe' /stext %TEMP%\mpvp.txt
- '%TEMP%\WBP.exe' /stext %TEMP%\WBVP.txt
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe' /tQ1Vb72t6bIX /%APPDATA%\Roaming\tQ1Vb72t6bIX\tQ1Vb72t6bIX.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %TEMP%\WBVP.txt
- <LS_APPDATA>\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\Policy.vpol
- %APPDATA%\Roaming\Microsoft\Protect\S-1-5-21-2832440558-3064306045-1455513625-1000\22f4970d-4a5b-487a-85f0-b5eba9e0de24
- %TEMP%\mespv.exe
- %APPDATA%\Roaming\tQ1Vb72t6bIX\tQ1Vb72t6bIX.xml
- %TEMP%\pvp.txt
- %TEMP%\pv.exe
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\User\28d9a34e-fa54-4601-a4dd-19c988a19326
- %TEMP%\WBP.exe
- %TEMP%\mpv.exe
- C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol
- \Device\Mup\BVNSEUHJ*\MAILSLOT\NET\NETLOGON
- C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch
- C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch
- %TEMP%\mespv.exe
- %TEMP%\pv.exe
- %TEMP%\pvp.txt
- %TEMP%\mpv.exe
- %TEMP%\WBP.exe
- %TEMP%\WBVP.txt
- DNS ASK dn#.##ftncsi.com
- DNS ASK sm##.gmail.com
- ClassName: 'Shell_TrayWnd' WindowName: ''