Техническая информация
- '<SYSTEM32>\wscript.exe' "%WINDIR%\Temp\amivccfpmb.js"
- %WINDIR%\temp\amivccfpmb.js
- http://ma###serix.com/angosz/cecolf.php?l=##########
- http://se###lcury.com/Toqis.php
- DNS ASK tr###micro.com
- DNS ASK ma###serix.com
- DNS ASK se###lcury.com
- ClassName: 'Ghost' WindowName: ''