Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\start0.exe
- '%TEMP%\svchoost.exe' -a 60 -o http://b.####nil.biz:8332/ -u mrdd_mrdd -p mama1 -t 2
- '%TEMP%\hstart.exe' /NOCONSOLE test.bat
- '%HOMEPATH%\Start Menu\Programs\Startup\start0.exe'
- '<SYSTEM32>\taskkill.exe' /f /im svchoost.exe
- '<SYSTEM32>\cmd.exe' /c test.bat
- %TEMP%\test.bat
- %TEMP%\svchoost.exe
- %TEMP%\hstart.exe
- 'b.###inil.biz':8332
- DNS ASK b.###inil.biz
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'