Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %TEMP%\delays.tmp
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- 'pr###.#ohnmccrea.com':80
- 'co###.hopto.org':80
- http://pr###.#ohnmccrea.com/
- http://pr###.#ohnmccrea.com//sql.dll
- http://co###.hopto.org/
- DNS ASK pr###.#ohnmccrea.com
- DNS ASK co###.hopto.org
- '%WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe'
- '%WINDIR%\syswow64\cmd.exe' /c timeout /t 10 & del /f /q "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" & rd /s /q "%ALLUSERSPROFILE%\JKFCBAEHCAEG" & exit (со скрытым окном)
- '%WINDIR%\syswow64\timeout.exe' /t 10