Техническая информация
- %TEMP%\pine.htm
- %TEMP%\terrorist.htm
- %TEMP%\marriage.htm
- %TEMP%\ampland.htm
- %TEMP%\horny.htm
- %TEMP%\suites.htm
- %TEMP%\entrance.htm
- %TEMP%\focuses.htm
- %TEMP%\country.htm
- %TEMP%\entrance.htm.bat
- %TEMP%\residential
- %TEMP%\steps
- %TEMP%\reached
- %TEMP%\columbus
- %TEMP%\handhelds
- %TEMP%\suggested
- %TEMP%\icon
- %TEMP%\webcams
- %TEMP%\review
- %TEMP%\fitting
- %TEMP%\cum
- %TEMP%\269276\az.com
- %TEMP%\269276\f
- %TEMP%\269276\f
- '34.##9.100.209':443
- DNS ASK Yc########McmirLh.YcEFTaZDUQMcmirLh
- '%TEMP%\269276\az.com' f
- '%WINDIR%\syswow64\cmd.exe' /c copy Entrance.htm Entrance.htm.bat & Entrance.htm.bat (со скрытым окном)
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' /I "opssvc wrsa"
- '%WINDIR%\syswow64\findstr.exe' "nsWscSvc ekrn bdservicehost SophosHealth AvastUI AVGUI & if not errorlevel 1 Set miGIzXs=AutoIt3.exe & Set xAHgXeIRR=.a3x & Set HSnbVkaeAymuKRIEfTyLeTDHPaZNZzDlHMBsHU=300
- '%WINDIR%\syswow64\extrac32.exe' /Y Pine.htm *.*
- '%WINDIR%\syswow64\findstr.exe' /V "GAMING" Suggested
- '%WINDIR%\syswow64\choice.exe' /d n /t 5