Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\ cnews.vbs
- %HOMEPATH%\documents\ v.ps1
- %HOMEPATH%\musicp.exe
- %TEMP%\is-29lgt.tmp\musicp.tmp
- %TEMP%\is-qdq0j.tmp\_isetup\_setup64.tmp
- %TEMP%\is-qdq0j.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-qdq0j.tmp\rdzone.dll
- %TEMP%\is-qdq0j.tmp\setup.exe
- %TEMP%\is-qdq0j.tmp\iuinstaller\setup.exe
- %TEMP%\mpb.cfg.44076.7447659491.ini
- %TEMP%\is-29lgt.tmp\musicp.tmp
- http://up####.iobit.com/infofiles/iu9/Freeware-iu9.upt
- DNS ASK up####.iobit.com
- DNS ASK dl.#####oxusercontent.com
- DNS ASK up######wsdate.myiphost.com
- ClassName: 'TFrmWizard' WindowName: ''
- '%HOMEPATH%\musicp.exe'
- '%TEMP%\is-29lgt.tmp\musicp.tmp' /SL5="$20358,21914979,137216,%HOMEPATH%\MusicP.exe"
- '%TEMP%\is-qdq0j.tmp\iuinstaller\setup.exe' /setup "%HOMEPATH%\MusicP.exe" "" "/Ver=9.6.0.3"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "%HOMEPATH%/Documents\ v.ps1"' (со скрытым окном)
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ cnews.vbs"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "%HOMEPATH%/Documents\ v.ps1"