Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\netsh.exe
- %HOMEPATH%\Start Menu\Programs\Startup\update.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\update.exe'
- '<SYSTEM32>\mode.com' con:cols=70 lines=28
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\run.bat"
- %APPDATA%\rtmpdump.exe
- %TEMP%\aut4.tmp
- %APPDATA%\run.bat
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'li####dou.no-ip.biz':24231
- DNS ASK li####dou.no-ip.biz
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'