Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Менеджер командной строки.lnk
- '%WINDIR%\Temp\Win64min\cmdow.exe' /RUN /HID win64min.exe -o ypool.net -u Allnyd.RIC_1 -p x -t 2
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\Temp\Win64min\settings.bat" "
- %WINDIR%\Temp\Win64min\win64min.exe
- %WINDIR%\Temp\Win64min\settings.bat
- %WINDIR%\Temp\Win64min\cmdow.exe
- ClassName: '' WindowName: '<SYSTEM32>\cmd.exe 1206402916'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''