Техническая информация
- '<SYSTEM32>\regsvr32.exe' -s C:\GN562Z\GW951Y\864.
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 972
- %TEMP%\1115266.cvr
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK wi##eam.org
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\regsvr32.exe' -s C:\GN562Z\GW951Y\864.' (со скрытым окном)