Техническая информация
- '<SYSTEM32>\taskkill.exe' /f /im "AdobeARM.exe" /t
- '<SYSTEM32>\taskkill.exe' /f /im "BCSSync.exe" /t
- %TEMP%\1.tmp\2.tmp\3.bat
- '16#.#43.206.6':445
- '16#.#43.206.6':139
- '16#.#43.206.6':80
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.tmp\3.bat" <Полный путь к файлу>"
- '<SYSTEM32>\net.exe' USE \\165.243.206.6 /USER:spot spot
- '%WINDIR%\regedit.exe' /s "\\165.243.206.6\software\???\w2k??\w2k up\SYSTEM\REG????.reg"
- '<SYSTEM32>\reg.exe' delete "hklm\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" /f
- '<SYSTEM32>\netsh.exe' wlan delete profile certify_gsshop