Техническая информация
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\st1m.bat" "
- '<SYSTEM32>\rundll32.exe' shell32.dll,Activate_RunDLL
- '<SYSTEM32>\attrib.exe'
- <SYSTEM32>\attrib.exe
- %TEMP%\st1m.bat
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'no###.mrbasic.com':80
- no###.mrbasic.com/pub/vok8u.avi
- DNS ASK no###.mrbasic.com
- ClassName: 'shell_traywnd' WindowName: '(null)'
