Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %TEMP%\eee.hta
- %TEMP%\eee.vbs
- %TEMP%\vmfreeze.exe
- 'vi#######.wikia.nocookie.net':80
- http://vi#######.wikia.nocookie.net/sims/images/0/0b/Hypnotoad.gif/revision/latest?cb###############
- DNS ASK vi#######.wikia.nocookie.net
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\eee.vbs"
- '%TEMP%\vmfreeze.exe'
- '%WINDIR%\syswow64\taskkill.exe' /f /im explorer.exe' (со скрытым окном)
- '%WINDIR%\syswow64\mshta.exe' "%TEMP%\eee.hta"