Техническая информация
- '<SYSTEM32>\taskkill.exe' /IM svchost.exe.exe /T /F
- '<SYSTEM32>\taskkill.exe' /f /im rutserv.exe
- '<SYSTEM32>\taskkill.exe' /f /im Rar.exe
- C:\Programdata\Microsoft\TaskList\System.exe
- C:\rdp\pause.bat
- C:\rdp\db.rar
- C:\Programdata\Microsoft\TaskList\whitelist.cfg
- C:\Programdata\Windows\rfusclient.exe
- C:\Programdata\Windows\install.bat
- C:\Programdata\Microsoft\TaskList\folders.cfg
- C:\rdp\Rar.exe
- %TEMP%\RarSFX0\R.vbs
- %TEMP%\RarSFX0\M.exe
- C:\Programdata\Install\st.vbs
- C:\Programdata\Microsoft\Intel\Cheat64.exe
- C:\rdp\run.vbs
- C:\Programdata\Microsoft\Intel\OS.bat
- C:\Programdata\Microsoft\Intel\Cheat32.exe
- C:\Programdata\Microsoft\Intel\Vegas.exe
- %TEMP%\dw.log
- C:\Programdata\Microsoft\rootsystem\P.vbs
- C:\Programdata\Microsoft\rootsystem\1.exe
- %TEMP%\2554A.dmp
- C:\Programdata\Microsoft\rootsystem\passwords.txt
- %TEMP%\B.tmp\C.bat
- C:\Programdata\Microsoft\rootsystem\P.exe
- C:\Programdata\Windows\vp8encoder.dll
- C:\Programdata\Windows\vp8decoder.dll
- C:\Programdata\Windows\rutserv.exe
- C:\Programdata\Windows\regedit.reg
- C:\Programdata\Microsoft\Intel\Vegas.sfx.exe
- %TEMP%\autA.tmp
- C:\Programdata\Windows\install.vbs
- C:\Programdata\Microsoft\Intel\fake.vbs
- C:\Programdata\Microsoft\Intel\winlogon.exe
- C:\Programdata\Microsoft\Intel\Temp.exe
- C:\Programdata\Microsoft\Intel\MOS.exe
- C:\Programdata\Microsoft\temp\H.bat
- C:\Programdata\Microsoft\temp\Clean.vbs
- C:\Programdata\Microsoft\Intel\P.exe
- C:\Programdata\Microsoft\Intel\smss.exe
- %TEMP%\aut2.tmp
- C:\Programdata\Microsoft\Intel\Cheat.exe
- %TEMP%\aut1.tmp
- C:\Programdata\Microsoft\Intel\winit.exe
- C:\Programdata\Microsoft\Intel\L.bat
- C:\Programdata\Microsoft\Check\Check.txt
- %TEMP%\aut3.tmp
- C:\Programdata\Microsoft\Intel\taskhost.exe
- C:\Programdata\Microsoft\Intel\System.exe
- C:\Programdata\Microsoft\Intel\svchost.exe
- C:\Programdata\Microsoft\Intel\Vega.exe
- C:\Programdata\Install\R.exe
- C:\Programdata\Install\st.bat
- C:\Programdata\System32\logs\svchost.exe
- %TEMP%\7.tmp\8.bat
- C:\Programdata\Microsoft\temp\Block.exe
- C:\Programdata\Microsoft\temp\5.xml
- C:\Programdata\Microsoft\temp\Temp.bat
- C:\Programdata\Microsoft\temp\Clean.bat
- C:\Programdata\Microsoft\Intel\R8.exe
- %TEMP%\4.tmp\5.bat
- C:\Programdata\Microsoft\Intel\R.exe
- C:\Programdata\Microsoft\Intel\taskhost.exe
- C:\Programdata\Microsoft\Intel\Temp.exe
- C:\Programdata\Microsoft\Intel\Vega.exe
- C:\Programdata\Microsoft\Intel\smss.exe
- C:\Programdata\Microsoft\Intel\svchost.exe
- C:\Programdata\Microsoft\Intel\System.exe
- C:\Programdata\Microsoft\Intel\Vegas.exe
- C:\Programdata\Microsoft\rootsystem\1.exe
- C:\Programdata\Microsoft\rootsystem\P.exe
- C:\Programdata\Microsoft\rootsystem\P.vbs
- C:\Programdata\Microsoft\Intel\Vegas.sfx.exe
- C:\Programdata\Microsoft\Intel\winit.exe
- C:\Programdata\Microsoft\Intel\winlogon.exe
- C:\Programdata\Microsoft\Intel\R8.exe
- %TEMP%\autA.tmp
- C:\Programdata\Microsoft\Intel\Cheat.exe
- C:\Programdata\Microsoft\Intel\Cheat32.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- C:\Programdata\Microsoft\Intel\Cheat64.exe
- C:\Programdata\Microsoft\Intel\OS.bat
- C:\Programdata\Microsoft\Intel\P.exe
- C:\Programdata\Microsoft\Intel\R.exe
- C:\Programdata\Microsoft\Intel\fake.vbs
- C:\Programdata\Microsoft\Intel\L.bat
- C:\Programdata\Microsoft\Intel\MOS.exe
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- 'C:\Programdata\Microsoft\TaskList\System.exe'
- 'C:\Programdata\Microsoft\Intel\Vega.exe'
- 'C:\Programdata\Microsoft\Intel\P.exe'
- 'C:\Programdata\Install\R.exe' -p123
- 'C:\Programdata\Microsoft\Intel\System.exe'
- '<SYSTEM32>\wscript.exe' "C:\rdp\run.vbs"
- 'C:\Programdata\Microsoft\Intel\Vegas.sfx.exe' -p123
- 'C:\Programdata\Microsoft\Intel\Vegas.exe'
- 'C:\Programdata\Microsoft\Intel\taskhost.exe'
- 'C:\Programdata\Microsoft\rootsystem\1.exe' /LoadPasswordsIE=1 /LoadPasswordsFirefox=1 /LoadPasswordsChrome=1 /LoadPasswordsOpera=1 /LoadPasswordsSafari=1 /LoadPasswordsSeaMonkey=1 /LoadPasswordsYandex=1 /stext passwords.txt
- 'C:\Programdata\Microsoft\rootsystem\P.exe'
- '<SYSTEM32>\wscript.exe' "c:\programdata\microsoft\rootsystem\P.vbs"
- '<SYSTEM32>\wscript.exe' "c:\Programdata\Windows\Install.vbs"
- 'C:\Programdata\Microsoft\Intel\R8.exe'
- 'C:\Programdata\Microsoft\Intel\smss.exe'
- 'C:\Programdata\Microsoft\Intel\winlogon.exe'
- '<SYSTEM32>\wscript.exe' "c:\programdata\microsoft\intel\fake.vbs"
- 'C:\Programdata\Microsoft\Intel\winit.exe' -p123
- 'C:\Programdata\Microsoft\Intel\Cheat.exe' -p123
- 'C:\Programdata\Microsoft\Intel\Temp.exe'
- '<SYSTEM32>\wscript.exe' "c:\programdata\microsoft\temp\Clean.vbs"
- 'C:\Programdata\Microsoft\Intel\MOS.exe'
- '<SYSTEM32>\wscript.exe' "c:\Programdata\Install\st.vbs"
- '%TEMP%\RarSFX0\M.exe'
- 'C:\Programdata\Microsoft\temp\Block.exe'
- 'C:\Programdata\Microsoft\Intel\svchost.exe'
- 'C:\Programdata\Microsoft\Intel\R.exe'
- '<SYSTEM32>\cmd.exe' /c C:\programdata\microsoft\temp\H.bat
- '<SYSTEM32>\cmd.exe' /c c:\programdata\microsoft\rootsystem\1.exe /LoadPasswordsIE=1 /LoadPasswordsFirefox=1 /LoadPasswordsChrome=1 /LoadPasswordsOpera=1 /LoadPasswordsSafari=1 /LoadPasswordsSeaMonkey=1 /LoadPasswo...
- '<SYSTEM32>\cmd.exe' /c ""C:\rdp\pause.bat" "
- '<SYSTEM32>\cmd.exe' /c ""c:\Programdata\Windows\install.bat" "
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\B.tmp\C.bat" c:\programdata\microsoft\intel\Vegas.exe"
- '<SYSTEM32>\cmd.exe' /c C:\programdata\microsoft\temp\Temp.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 540
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOAProtection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\4.tmp\5.bat" c:\programdata\microsoft\intel\smss.exe"
- '<SYSTEM32>\cmd.exe' /c ""c:\programdata\microsoft\intel\L.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7.tmp\8.bat" c:\programdata\microsoft\intel\winlogon.exe"
- '<SYSTEM32>\sc.exe' delete swprv
- '<SYSTEM32>\cmd.exe' /c ""c:\ProgramData\microsoft\Temp\Clean.bat" "
- '<SYSTEM32>\cmd.exe' /c ""c:\ProgramData\Install\st.bat" "