Техническая информация
- '<SYSTEM32>\net1.exe' user "%USERNAME%" "134134"
- '<SYSTEM32>\wbem\wmic.exe' useraccount where name='%USERNAME%' call Rename "ПлЦЄµАГЬВлБЄПµQQ67556883"
- '<SYSTEM32>\net.exe' user "%USERNAME%" "134134"
- '<SYSTEM32>\cmd.exe' /c net user "%USERNAME%" "134134"
- '<SYSTEM32>\cmd.exe' /c wmic useraccount where name='%USERNAME%' call Rename "ПлЦЄµАГЬВлБЄПµQQ67556883"
- %TEMP%\tmp1.tmp
- %TEMP%\tmp2.tmp
- %WINDIR%\ME\ГОчКФґВл.ico
- %WINDIR%\SkinH_EL.dll
- %WINDIR%\ME\ГОчКДЈїй.ico
- %WINDIR%\ME\ГОчКФґВл.ico
- %WINDIR%\ME\ГОчКДЈїй.ico
- %WINDIR%\SkinH_EL.dll
- %TEMP%\tmp1.tmp
- 'ft#.#ree3v.net':21
- 'localhost':1036
- DNS ASK ft#.#ree3v.net