Technical Information
- '<SYSTEM32>\net.exe' stop sharedaccess
- %TEMP%\~1.bat
- %WINDIR%\pand.txt
- <Current directory>\ftp.txt
- <Current directory>\123.txt
- <SYSTEM32>\zz.vbs
- %APPDATA%\Spiritsoft\urlspirit\product.dat
- %TEMP%\~1.bat
- <Current directory>\ftp.txt
- <Current directory>\123.txt
- 'localhost':1037
- 'localhost':1039
- 'go#.gl':80
- 'te###.crocserve.com':21
- http://go#.gl/ewgWF
- DNS ASK go#.gl
- DNS ASK te###.crocserve.com
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c %TEMP%\~1.bat <Full path to file>
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\ftp.exe' -s:ftp.txt
- '<SYSTEM32>\cmd.exe' /c type "<SYSTEM32>\vvtn.txt"