Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\twainresolver.lnk
- '<SYSTEM32>\cmd.exe' /c cd field_dir & "%ALLUSERSPROFILE%\drivertoolkit\drivertoolkit.tmp"
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1612
- %ALLUSERSPROFILE%\drivertoolkit\drivertoolkit.zip
- %ProgramFiles%\driver~1\drivertoolkit.tmp
- %ProgramFiles%\driver~1\drivertoolkit.mof
- %ProgramFiles%\driver~1\drivertoolkit.rsp
- %ProgramFiles%\driver~1\drivertoolkit.bin
- %ALLUSERSPROFILE%\twainresolver\twainresolver.scr
- %HOMEPATH%\documents\vb3b5d.tmp
- %TEMP%\1069184.cvr
- %TEMP%\vb3b5c.tmp
- %HOMEPATH%\documents\vb3b5d.tmp в %TEMP%\vb3b5c.tmp
- http://is##ddp.com/rEmt1t_pE7o_pe0Ry/hipto.php
- DNS ASK is##ddp.com
- '%ALLUSERSPROFILE%\twainresolver\twainresolver.scr' /S
- '<SYSTEM32>\cmd.exe' /c cd field_dir & "%ALLUSERSPROFILE%\drivertoolkit\drivertoolkit.tmp"' (со скрытым окном)
- '%ALLUSERSPROFILE%\twainresolver\twainresolver.scr' /S' (со скрытым окном)