Техническая информация
- %TEMP%\content\4328-4880-wscript.exe-19-50-21-177.dump
- %TEMP%\lfpmkusf\lfpmkusf.0.cs
- %TEMP%\lfpmkusf\lfpmkusf.cmdline
- %TEMP%\lfpmkusf\lfpmkusf.out
- %TEMP%\lfpmkusf\csc68c7556cda4440989ce631438058f0.tmp
- %TEMP%\resb1cc.tmp
- %TEMP%\lfpmkusf\lfpmkusf.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBCAGUAZgBqAGUAbABzAGUAcwBkACAAUABoAHIAZQBuAGkAYwBzAGwAIABUAHIAYQBuAHMAcwAgAFQAYQBiAHUAbABlAHIAaQBuACAASgB2AG4AZgByAGkAbgBnAGUAcgAgAEUAZgB0AGUAcgB2AGUAZQByACAAQwB5AHQAYQBzAHQA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\lfpmkusf\lfpmkusf.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB1CC.tmp" "%TEMP%\lfpmkusf\CSC68C7556CDA4440989CE631438058F0.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBCAGUAZgBqAGUAbABzAGUAcwBkACAAUABoAHIAZQBuAGkAYwBzAGwAIABUAHIAYQBuAHMAcwAgAFQAYQBiAHUAbABlAHIAaQBuACAASgB2AG4AZgByAGkAbgBnAGUAcgAgAEUAZgB0AGUAcgB2AGUAZQByACAAQwB5AHQAYQBzAHQA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\lfpmkusf\lfpmkusf.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB1CC.tmp" "%TEMP%\lfpmkusf\CSC68C7556CDA4440989CE631438058F0.TMP"