Техническая информация
- %TEMP%\autdef9.tmp
- %TEMP%\badwarepaidwoofer.exe
- %TEMP%\aute189.tmp
- %TEMP%\server.crt
- %TEMP%\aute18a.tmp
- %TEMP%\badwarecheck.bat
- nul
- %TEMP%\autdef9.tmp
- %TEMP%\aute189.tmp
- %TEMP%\aute18a.tmp
- %TEMP%\badwarepaidwoofer.exe
- %TEMP%\server.crt
- %TEMP%\badwarecheck.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "Import-Certificate -FilePath '%TEMP%\server.crt' -CertStoreLocation 'Cert:\LocalMachine\Root' -ErrorAction SilentlyContinue"
- '%TEMP%\badwarepaidwoofer.exe'
- '<SYSTEM32>\cmd.exe' /c @echo off & echo Running badwarecheck.bat silently... & start "" /min /b cmd /c "%TEMP%\badwarecheck.bat & exit"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c @echo off & echo Running badwarecheck.bat silently... & start "" /min /b cmd /c "%TEMP%\badwarecheck.bat & exit"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\badwarecheck.bat & exit"
- '<SYSTEM32>\certutil.exe' -store TrustedRoot
- '<SYSTEM32>\findstr.exe' /i /c:"%TEMP%\server.crt"
- '<SYSTEM32>\findstr.exe' /C:"188.227.86.96 keyauth.win" "<DRIVERS>\etc\hosts"
- '<SYSTEM32>\ipconfig.exe' /flushdns