Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\hahahahaha.exe
- '%TEMP%\abc\mamita.exe' -a 59 -g yes -o http://b.####nil.biz:8332/ -u redem_guild -p redem -t 2
- '%TEMP%\abc\hsbc.exe' /NOCONSOLE %TEMP%\abc\hakonamatata.cmd
- '%HOMEPATH%\Start Menu\Programs\Startup\hahahahaha.exe'
- '<SYSTEM32>\taskkill.exe' /f /im mamita.exe
- '<SYSTEM32>\taskkill.exe' /f /im svchoost.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\abc\hakonamatata.cmd
- %TEMP%\abc\hakonamatata.cmd
- %TEMP%\abc\mamita.exe
- %TEMP%\abc\hsbc.exe
- 'b.###inil.biz':8332
- DNS ASK b.###inil.biz
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'