Техническая информация
- '<SYSTEM32>\wscript.exe' "%APPDATA%\.%USERNAME%\lnk201131.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\.%USERNAME%\lnk230365.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\lnk581249.vbs"
- '%APPDATA%\.%USERNAME%\ \MjY2.exe'
- '<SYSTEM32>\attrib.exe' "%APPDATA%\.%USERNAME%\ " +s +h
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\.%USERNAME%\bat764886.bat""
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\.%USERNAME%\bat266750.bat""
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\bat167543.bat""
- '<SYSTEM32>\cmd.exe' /k ping 1.1.1.1 -n 1 -w 2410&start /b "" "%APPDATA%\.%USERNAME%\ \MjY2.exe" -p&exit&
- '<SYSTEM32>\attrib.exe' "%APPDATA%\.%USERNAME%" +s +h
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 2410
- %APPDATA%\.%USERNAME%\lnk230365.vbs
- %APPDATA%\.%USERNAME%\bat266750.bat
- %APPDATA%\.%USERNAME%\lnk201131.vbs
- %APPDATA%\.%USERNAME%\bat764886.bat
- %APPDATA%\lnk581249.vbs
- %APPDATA%\bat167543.bat
- %APPDATA%\.%USERNAME%\ \MjY2.exe
- %APPDATA%\.%USERNAME%\winupdate :.file
- ClassName: 'Shell_TrayWnd' WindowName: ''