Technical Information
- '<SYSTEM32>\net.exe' stop AdobeFlashPlayerHash
- <SYSTEM32>\HS\parameters.ini
- %TEMP%\nsx2.tmp\nsisdl.dll
- <SYSTEM32>\HS\HS_Svc.exe
- %TEMP%\nsx2.tmp\nsExec.dll
- %TEMP%\nsx2.tmp\ns3.tmp
- %TEMP%\nsx2.tmp\ns4.tmp
- <SYSTEM32>\HS\install.log
- %TEMP%\nsx2.tmp\ns3.tmp
- 'ha####remload.ru':80
- http://ha####remload.ru/pocket/HS_Svc.exe
- DNS ASK ha####remload.ru
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%TEMP%\nsx2.tmp\ns3.tmp' <SYSTEM32>\cmd.exe /C net stop AdobeFlashPlayerHash>install.log
- '%TEMP%\nsx2.tmp\ns4.tmp' <SYSTEM32>\cmd.exe /C Sc delete AdobeFlashPlayerHash>>install.log
- '<SYSTEM32>\cmd.exe' /C net stop AdobeFlashPlayerHash>install.log
- '<SYSTEM32>\net1.exe' stop AdobeFlashPlayerHash
- '<SYSTEM32>\cmd.exe' /C Sc delete AdobeFlashPlayerHash>>install.log
- '<SYSTEM32>\sc.exe' delete AdobeFlashPlayerHash