Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\mOOKsZiLHt'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath 'C:\Users'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%WINDIR%'"
- '%APPDATA%\adobe-genр-v3.6.9.exe' (загружен из сети Интернет)
- %APPDATA%\adobe-genp-v3.6.9.exe
- %APPDATA%\adobe-genр-v3.6.9.exe
- %TEMP%\aut4547.tmp
- %APPDATA%\config.ini
- %LOCALAPPDATA%\mookszilht\tadwagwe.exe
- '17#.#8.185.8':5858
- http://17#.##.185.8:5858/nix.exe via 17#.#8.185.8
- ClassName: 'Edit' WindowName: ''
- '%APPDATA%\adobe-genр-v3.6.9.exe'
- '%APPDATA%\adobe-genp-v3.6.9.exe'
- '%LOCALAPPDATA%\mookszilht\tadwagwe.exe'