Техническая информация
- '<SYSTEM32>\wscript.exe' %PROGRAMDATA%\program_data_index.vbs
- '<SYSTEM32>\cmd.exe' /c wscript %PROGRAMDATA%\program_data_index.vbs & wscript %PROGRAMDATA%\internal_fcp_util.vbs
- %PROGRAMDATA%\program_data_index.vbs
- %PROGRAMDATA%\internal_fcp_util.vbs
- http://18#.#43.115.67/comment.txt
- DNS ASK gi##ub.com
- '<SYSTEM32>\wscript.exe' %PROGRAMDATA%\internal_fcp_util.vbs
- '<SYSTEM32>\cmd.exe' /c wscript %PROGRAMDATA%\program_data_index.vbs & wscript %PROGRAMDATA%\internal_fcp_util.vbs' (со скрытым окном)