Техническая информация
- '<SYSTEM32>\ping.exe' -n 7 localhost
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\selfdel0.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\batfile.bat" "
- '<SYSTEM32>\wscript.exe' "%TEMP%\dl.vbs"
- C:\test.exe
- %TEMP%\selfdel0.bat
- %TEMP%\1.tmp\batfile.bat
- %TEMP%\dl.vbs
- %TEMP%\1.tmp\batfile.bat
- 'de######efreak.de.funpic.de':80
- de######efreak.de.funpic.de/test.exe
- DNS ASK de######efreak.de.funpic.de
- ClassName: 'Shell_TrayWnd' WindowName: ''