Техническая информация
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\HighScores.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1456
- <SYSTEM32>\wermgr.exe
- %WINDIR%\syswow64\cmd.exe
- %ALLUSERSPROFILE%\highscores.bat
- %TEMP%\1161973.cvr
- C:\trone\altogether4127453.vbs
- C:\trone\1\existingexcel.dll
- '12#.2.28.70':449
- 'wt###myip.com':80
- '12#.2.28.70':449
- DNS ASK wt###myip.com
- DNS ASK 19#.###.#11.95.zen.spamhaus.org
- DNS ASK 19#.###.#11.95.cbl.abuseat.org
- '<SYSTEM32>\wscript.exe' "C:\trone\altogether4127453.vbs"
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\HighScores.bat' (со скрытым окном)
- '<SYSTEM32>\ping.exe' w 5000 ya.fr
- '<SYSTEM32>\ping.exe' w 5000 htr-oi.io
- '<SYSTEM32>\rundll32.exe' c:\trone\1\ExistingExcel.dll,DllRegisterServer1
- '<SYSTEM32>\wermgr.exe'