Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\host32.exe
- '<SYSTEM32>\wscript.exe' "%TEMP%\C\s.vbs"
- '%TEMP%\cyber64.exe'
- '%HOMEPATH%\Start Menu\Programs\Startup\host32.exe'
- '%TEMP%\C\wallhack.exe'
- '%TEMP%\lite64.exe' -pwr
- %TEMP%\lite64.exe
- %TEMP%\cyber64.exe
- %TEMP%\C\wallhack.exe
- %TEMP%\C\s.vbs
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''