Техническая информация
- '%WINDIR%\Temp\ATSCallingCard_2.0.exe'
- '%WINDIR%\Temp\wget.exe' Http://ic######.#dvancedtechsupport.com/ATSCallingCard_2.0.exe
- '%WINDIR%\Temp\ATSCallingCard_2.0.exe' (загружен из сети Интернет)
- '<SYSTEM32>\taskkill.exe' /F /IM ATSHotKey.exe /T
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\Temp\call.bat" "
- %WINDIR%\Temp\ATSCallingCard_2.0.exe
- %WINDIR%\Temp\call.bat
- %WINDIR%\Temp\wget.exe
- 'ic######.#dvancedtechsupport.com':80
- ic######.#dvancedtechsupport.com/ATSCallingCard_2.0.exe
- DNS ASK ic######.#dvancedtechsupport.com
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'