Техническая информация
- '%ALLUSERSPROFILE%\DRM\XXX\.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160804.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160759.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160809.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160819.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160814.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160754.jpg
- %ALLUSERSPROFILE%\DRM\XXX\cacybbzcwpxbbxg
- %ALLUSERSPROFILE%\DRM\XXX\.exe
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160739.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160749.jpg
- %ALLUSERSPROFILE%\DRM\XXX-SCREEN\%USERNAME%\20140422160744.jpg
- 'localhost':12345
- 'localhost':12345