Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath \"%TEMP%\nsw4DF1.tmp\""
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsw4df1.tmp\nsexec.dll
- %TEMP%\nsw4df1.tmp\ikogehal.dat
- %TEMP%\nsw4df1.tmp\xnzimscfld.exe
- %TEMP%\nsw4df1.tmp\xnzimscfld.exe.config
- %TEMP%\nsw4df1.tmp\selfdel.dll
- %TEMP%\nsw4df1.tmp\ikogehal.dat
- %TEMP%\nsw4df1.tmp\nsexec.dll
- %TEMP%\nsw4df1.tmp\selfdel.dll
- %TEMP%\nsw4df1.tmp\xnzimscfld.exe
- %TEMP%\nsw4df1.tmp\xnzimscfld.exe.config
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath \"%TEMP%\nsw4DF1.tmp\"" (со скрытым окном)