Техническая информация
- '<SYSTEM32>\wscript.exe' "%LOCALAPPDATA%\Temp10.vbs"
- %TEMP%\bg4.jpg
- %LOCALAPPDATA%\temp10.vbs
- 'al#.##aceland.edu':80
- http://al#.##aceland.edu/~belmore/lily.jpg
- http://al#.##aceland.edu/~belmore/sample3.vbs
- DNS ASK al#.##aceland.edu
- '<SYSTEM32>\rundll32.exe' user32.dll,UpdatePerUserSystemParameters