Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Event Instrument log] 'Start' = '00000002'
- '%PROGRAM_FILES%\WmiPrvsc.exe Д¬ИП·ЦЧй' NewRunApp
- '%PROGRAM_FILES%\WmiPrvsc.exe Д¬ИП·ЦЧй'
- '<SYSTEM32>\wscript.exe' "C:\760.vbs"
- C:\760.vbs
- %PROGRAM_FILES%\WmiPrvsc.exe Д¬ИП·ЦЧй
- C:\760.vbs
- 'www.ha##yh.net':41523
- DNS ASK www.ha##yh.net