Техническая информация
- <SYSTEM32>\conhost.exe
- %APPDATA%\password.bat
- %APPDATA%\greensteam.sfx.exe
- C:\greensteam.exe
- '34.##9.100.209':443
- ClassName: 'Edit' WindowName: ''
- '%APPDATA%\greensteam.sfx.exe' -p1111 -dc:\
- 'C:\greensteam.exe'
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\password.bat" "