Техническая информация
- %CommonProgramFiles%\sfbsbvy\coiome.exe
- <SYSTEM32>\sc.exe delete JavaServe
- <SYSTEM32>\taskkill.exe /im iejore.exe /f
- <SYSTEM32>\mshta.exe "%PROGRAM_FILES%\NYD.hta"
- <SYSTEM32>\taskkill.exe /im coiome.exe /f
- %HOMEPATH%\Desktop\2345НшЦ·µјєЅ.url
- %CommonProgramFiles%\sfbsbvy\coiome.exe
- %PROGRAM_FILES%\NYD.hta
- %PROGRAM_FILES%\NYD.hta
- 'a1#.##uisumuli.com':53
- DNS ASK a1#.##uisumuli.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''