Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\xD.exe
- '%TEMP%\hid.exe' /NOCONSOLE vx.bat
- '%TEMP%\hehe.exe' -a 60 -g yes -o http://hd##.####rium-stakany.org:8332/ -u darkSons_crypt -p blabblabla -t 2
- '%TEMP%\2.exe'
- '%HOMEPATH%\Start Menu\Programs\Startup\xD.exe'
- '%TEMP%\1.exe'
- '<SYSTEM32>\cmd.exe' /c vx.bat
- '<SYSTEM32>\cmd.exe' /c %TEMP%\UNI2.tmp.bat
- '<SYSTEM32>\cmd.exe' /c %TEMP%\UNI1.tmp.bat
- %TEMP%\1.exe
- %TEMP%\UNI1.tmp.bat
- %TEMP%\UNI2.tmp.bat
- %TEMP%\2.exe
- %TEMP%\vx.bat
- %TEMP%\hid.exe
- %TEMP%\hehe.exe
- %TEMP%\2.exe
- %TEMP%\1.exe
- 'hd##.###arium-stakany.org':8332
- DNS ASK hd##.###arium-stakany.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'