Техническая информация
- %TEMP%\msdevj.exe
- <SYSTEM32>\wscript.exe %TEMP%\\t_153984.vbs
- <SYSTEM32>\wscript.exe %TEMP%\\t_154640.vbs
- <SYSTEM32>\wscript.exe %TEMP%\\t_155328.vbs
- <SYSTEM32>\cmd.exe /c ""%TEMP%\Del.bat" "
- <SYSTEM32>\ping.exe -n 3 127.0.0.1
- <SYSTEM32>\wscript.exe %TEMP%\\t_153453.vbs
- %TEMP%\t_153984.vbs
- %TEMP%\t_154640.vbs
- %TEMP%\t_155328.vbs
- %TEMP%\t_153453.vbs
- %TEMP%\msdevj.exe
- %TEMP%\Del.dat
- %TEMP%\Del.bat
- %TEMP%\Del.dat
- 'vi#.#aqio.com':9999
- DNS ASK vi#.#aqio.com
- ClassName: 'Shell_TrayWnd' WindowName: ''