Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\wlanext.exe'
- %APPDATA%\wlanext.exe
- '23.##.235.86':80
- http://23.##.235.86/wmn/Microsoftdecideddeleteeverythingfromthepccachecookiechistory.Doc
- http://23.##.235.86/400/wlanext.exe
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle minimized $fat32 = Get-Content '%LOCALAPPDATA%\preoppression\Kleres81\Favorite.Vej' ; powershell.Exe "$fat32"' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle minimized $fat32 = Get-Content '%LOCALAPPDATA%\preoppression\Kleres81\Favorite.Vej' ; powershell.Exe "$fat32"