Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\santa.bat
- '%WINDIR%\syswow64\net.exe' stop wscsvc
- %TEMP%\nsl388e.tmp
- %TEMP%\nsl388f.tmp\esetnsmart.exe
- %WINDIR%\syswow64\msinet.ocx
- %WINDIR%\syswow64\esetnsmart.txt
- %APPDATA%\microsoft\windows\start menu\programs\startup\santa.bat
- %TEMP%\nsl388f.tmp\esetnsmart.exe
- DNS ASK bo###oul.com
- '%TEMP%\nsl388f.tmp\esetnsmart.exe'
- '%WINDIR%\syswow64\net1.exe' stop wscsvc
- '%WINDIR%\syswow64\net.exe' stop wscsvc (со скрытым окном)