Техническая информация
- '%WINDIR%\Temp\ping.exe' 6789 sock 9876 -Hide
- '%WINDIR%\Temp\HIDECMD.EXE' ping.bat
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\net.exe' stop sharedaccess
- '<SYSTEM32>\cmd.exe' /c ping.bat
- %WINDIR%\Temp\ping.exe
- %WINDIR%\Temp\start.lnk
- %WINDIR%\Temp\HIDECMD.EXE
- %WINDIR%\Temp\ping.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''