Technical Information
- '<SYSTEM32>\net.exe' stop YandexService
- <Current directory>\comdlg32.ocx
- C:\1.txt
- <SYSTEM32>\dnsipver.txt
- <Current directory>\ys.dat
- <SYSTEM32>\yandexservice.exe
- <SYSTEM32>\dnsipver.txt
- C:\1.txt
- DNS ASK ba##ash.ru
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c Echo 11111> c:\1.txt' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net stop YandexService & takeown /f "<SYSTEM32>\yandexservice.exe" & icacls "<SYSTEM32>\yandexservice.exe" /grant user:F /c' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c Echo 11111> c:\1.txt
- '<SYSTEM32>\cmd.exe' /c net stop YandexService & takeown /f "<SYSTEM32>\yandexservice.exe" & icacls "<SYSTEM32>\yandexservice.exe" /grant user:F /c
- '<SYSTEM32>\net1.exe' stop YandexService