Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath '%ProgramFiles(x86)%\Spring-Rain'
- %TEMP%\nspca32.tmp\nsisdl.dll
- %ProgramFiles(x86)%\spring-rain\7zxa.dll
- %ProgramFiles(x86)%\spring-rain\7za.dll
- %ProgramFiles(x86)%\spring-rain\7za.exe
- %ProgramFiles(x86)%\spring-rain\winamp.7z
- %ProgramFiles(x86)%\spring-rain\winamp.7z
- %TEMP%\nspca32.tmp\nsisdl.dll
- DNS ASK ch#####.amazonaws.com
- '%ProgramFiles(x86)%\spring-rain\7za.exe' e -p winamp.7z
- '%ProgramFiles(x86)%\spring-rain\7za.exe' e -p winamp.7z (со скрытым окном)