Техническая информация
- [HKLM\Software\Classes\Counsellor\Shell\Open\Command] '' = 'wscript.exe //E:vbscript "%1"'
- %TEMP%\upgrader.exe
- %TEMP%\035c6c48-41dd-c9e3-cf5e-025c5bcd6717.bat
- nul
- %WINDIR%\temp\upgrader.back
- %APPDATA%\microsoft\windows\start menu\programs\microsoft date tools upgrader.back
- %TEMP%\upgrader.exe
- '16#.#4.97.90':443
- '16#.#4.97.90':443
- '%TEMP%\upgrader.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\035c6c48-41dd-c9e3-cf5e-025c5bcd6717.bat" "' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\035c6c48-41dd-c9e3-cf5e-025c5bcd6717.bat" "
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\cmd.exe' /c subst I: "%APPDATA%\Microsoft\Windows\Start Menu\Programs"
- '<SYSTEM32>\subst.exe' I: "%APPDATA%\Microsoft\Windows\Start Menu\Programs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online