Technical Information
- '<SYSTEM32>\taskkill.exe' /F /IM AdMunch.exe
- '<SYSTEM32>\taskkill.exe' /F /IM AdMunch64.exe
- '<SYSTEM32>\taskkill.exe' /F /IM AM32-33707.dll
- '<SYSTEM32>\taskkill.exe' /F /IM AM64-33707.dll
- '<SYSTEM32>\taskkill.exe' /F /IM AdMunch.dll
- %TEMP%\1.tmp\amupdate.cmd
- <Current directory>\wget.exe
- <Current directory>\AM.adl
- 'pr##az.ru':80
- http://pr##az.ru/wp-content/files/AM.adl
- DNS ASK pr##az.ru
- ClassName: '' WindowName: ''
- '<Current directory>\wget.exe' -cN -t10 -T15 "http://pr##az.ru/wp-content/files/AM.adl"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\amupdate.cmd" "