Техническая информация
- regasm.exe
- %TEMP%\decimal
- %TEMP%\45912\simpson.pif
- %TEMP%\chains
- %TEMP%\columns
- %TEMP%\donate
- %TEMP%\enhancement
- %TEMP%\taylor
- %TEMP%\teddy
- %TEMP%\45912\h
- %TEMP%\cingular
- %TEMP%\tumor
- %TEMP%\brakes
- %TEMP%\concert
- %TEMP%\who
- %TEMP%\jeans
- %TEMP%\them
- %TEMP%\ana
- %TEMP%\aspnet
- %TEMP%\45912\regasm.exe
- %TEMP%\45912\h
- %TEMP%\them в %TEMP%\them.cmd
- DNS ASK aK##############sWcRXxjZAlPv.aKwBETNQYoQQjihEsWcRXxjZAlPv
- '%TEMP%\45912\simpson.pif' H
- '%TEMP%\45912\regasm.exe'
- '%WINDIR%\syswow64\cmd.exe' /k move Them Them.cmd & Them.cmd & exit (со скрытым окном)
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' /I "wrsa.exe opssvc.exe"
- '%WINDIR%\syswow64\findstr.exe' /I "avastui.exe avgui.exe bdservicehost.exe ekrn.exe nswscsvc.exe sophoshealth.exe"
- '%WINDIR%\syswow64\cmd.exe' /c md 45912
- '%WINDIR%\syswow64\findstr.exe' /V "LUXEMBOURGCUSTOMIZEDTANKMIDI" Chains
- '%WINDIR%\syswow64\cmd.exe' /c copy /b ..\Who + ..\Jeans + ..\Teddy + ..\Aspnet + ..\Enhancement + ..\Donate + ..\Cingular + ..\Ana + ..\Concert + ..\Taylor + ..\Tumor + ..\Brakes + ..\Decimal H
- '%WINDIR%\syswow64\choice.exe' /d y /t 5