Техническая информация
- %TEMP%\darova.exe
- %TEMP%\darova.sfx.exe
- %TEMP%\ar.bat
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\darova.exe'
- '%TEMP%\darova.sfx.exe' -p6565 -d%HOMEPATH%\Local Settings\Temp
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7zS83B638A2\darova.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\ar.bat" "