Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'KASHTRWNT952407547840411' = '"%ProgramFiles%\Kaseya\TRWNT952407547840411\KaUsrTsk.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\KATRWNT952407547840411] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\KATRWNT952407547840411] 'ImagePath' = '"%ProgramFiles%\Kaseya\TRWNT952407547840411\AgentMon.exe"'
- %TEMP%\KASetup.log
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KaseyaD.ini
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KaseyaFW.ini
- %ProgramFiles%\Kaseya\TRWNT952407547840411\custom\online.ico
- %ProgramFiles%\Kaseya\TRWNT952407547840411\custom\blink.ico
- %ProgramFiles%\Kaseya\TRWNT952407547840411\custom\noremote.ico
- %ProgramFiles%\Kaseya\TRWNT952407547840411\custom\offline.ico
- %ProgramFiles%\Kaseya\TRWNT952407547840411\libeay32.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\knetmon.sys
- %ProgramFiles%\Kaseya\TRWNT952407547840411\ssleay32.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\KLua.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\KLuaMessages.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\lsqlite3.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\Lua.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\LuaLib.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\knetmon64.sys
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\KaseyaSP.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\audit.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KaUsrTsk.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\kGetELMg64.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KPrtPng.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\libkacm.dgst
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\askUser.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KASetup.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\curl.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KAgentExt.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\libkacm.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\KaseyaD.VXD
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\KAPFA.sys
- %ProgramFiles%\Kaseya\TRWNT952407547840411\drivers\KAPFA64.sys
- %ProgramFiles%\Kaseya\TRWNT952407547840411\KEventLog.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\LogParser.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\sporder.dll
- %TEMP%\pft3.tmp\extensions\scripts\socket\url.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\database.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\XmlToLua.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\xpath.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\mime\core.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\core.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\ftp.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\http.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\Utility.lua
- %TEMP%\pft3.tmp\ssleay32.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\ToTypes.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\ssl\https.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\database\schedules.db
- %ProgramFiles%\Kaseya\TRWNT952407547840411\database\procs.db
- %ProgramFiles%\Kaseya\TRWNT952407547840411\Package.xml
- <DRIVERS>\KAPFA.sys
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\tp.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\smtp.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\AgentMon.exe
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\MakeDirManifest.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\email.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\evaluateExpression.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\File.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\KXmpp.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\ltn12.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\ssl.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\debugger.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\debugintrospection.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\mime.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\scheduler.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\sconvert.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\scriptRunner.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\showMessage.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\LuaXml.lua
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\lfs.dll
- %TEMP%\pft3.tmp\sporder.dll
- %TEMP%\pft3.tmp\Psapi.Dll
- %TEMP%\pft3.tmp\LogParser.dll
- %TEMP%\pft3.tmp\extensions\scripts\database.lua
- %TEMP%\pft3.tmp\extensions\scripts\debugger.lua
- %TEMP%\pft3.tmp\extensions\scripts\debugintrospection.lua
- %TEMP%\pft3.tmp\extensions\scripts\email.lua
- %TEMP%\pft3.tmp\extensions\LuaLib.dll
- %TEMP%\pft3.tmp\custom\blink.ico
- %TEMP%\pft3.tmp\extensions\scripts\audit.lua
- %TEMP%\pft3.tmp\extensions\scripts\evaluateExpression.lua
- %TEMP%\pft3.tmp\extensions\scripts\ltn12.lua
- %TEMP%\pft3.tmp\extensions\scripts\LuaXml.lua
- %TEMP%\pft3.tmp\extensions\scripts\MakeDirManifest.lua
- %TEMP%\pft3.tmp\extensions\scripts\mime\core.dll
- %TEMP%\pft3.tmp\extensions\scripts\File.lua
- %TEMP%\pft3.tmp\extensions\scripts\KXmpp.lua
- %TEMP%\pft3.tmp\extensions\scripts\lfs.dll
- <SYSTEM32>\KaseyaSP.dll
- %TEMP%\pft3.tmp\extensions\scripts\mime.lua
- %TEMP%\pft3.tmp\extensions\KLuaMessages.dll
- %TEMP%\pft3.tmp\extensions\KLua.dll
- %TEMP%\pft3.tmp\database\schedules.db
- %TEMP%\pft3.tmp\database\procs.db
- %TEMP%\pft3.tmp\custom\online.ico
- %TEMP%\pft3.tmp\custom\offline.ico
- %TEMP%\pft3.tmp\custom\noremote.ico
- %TEMP%\pft3.tmp\extensions\Lua.exe
- %TEMP%\pft3.tmp\curl.exe
- %TEMP%\pft3.tmp\AgentMon.exe
- %TEMP%\pft3.tmp\pftw1.pkg
- %TEMP%\plf1.tmp
- %TEMP%\ext2.tmp
- %TEMP%\KaseyaD.ini
- %TEMP%\KAgentSilent.exe
- %TEMP%\pft3.tmp\extensions\lsqlite3.dll
- %ProgramFiles%\Kaseya\TRWNT952407547840411\extensions\scripts\socket\url.lua
- %TEMP%\pft3.tmp\extensions\scripts\remoteDebugger.lua
- %TEMP%\pft3.tmp\extensions\scripts\scriptRunner.lua
- %TEMP%\pft3.tmp\KaseyaD.ini
- %TEMP%\pft3.tmp\KaseyaD.VXD
- %TEMP%\pft3.tmp\KaseyaFW.ini
- %TEMP%\pft3.tmp\KaseyaSP.dll
- %TEMP%\pft3.tmp\KaUsrTsk.exe
- %TEMP%\pft3.tmp\extensions\scripts\scheduler.lua
- %TEMP%\pft3.tmp\KASetup.exe
- %TEMP%\pft3.tmp\kapfa64.sys
- %TEMP%\pft3.tmp\knetmon64.sys
- %TEMP%\pft3.tmp\KPrtPng.exe
- %TEMP%\pft3.tmp\libeay32.dll
- %TEMP%\pft3.tmp\libkacm.dgst
- %TEMP%\pft3.tmp\libkacm.dll
- %TEMP%\pft3.tmp\KEventLog.dll
- %TEMP%\pft3.tmp\knetmon.sys
- %TEMP%\pft3.tmp\extensions\scripts\sconvert.lua
- %TEMP%\pft3.tmp\kGetELMg64.exe
- %TEMP%\pft3.tmp\extensions\scripts\askUser.lua
- %TEMP%\pft3.tmp\extensions\scripts\showMessage.lua
- %TEMP%\pft3.tmp\extensions\scripts\socket\core.dll
- %TEMP%\pft3.tmp\extensions\scripts\socket\ftp.lua
- %TEMP%\pft3.tmp\extensions\scripts\socket\http.lua
- %TEMP%\pft3.tmp\extensions\scripts\socket\smtp.lua
- %TEMP%\pft3.tmp\extensions\scripts\xpath.lua
- %TEMP%\pft3.tmp\KaPFA.sys
- %TEMP%\pft3.tmp\KAgentExt.dll
- %TEMP%\pft3.tmp\extensions\scripts\ssl\https.lua
- %TEMP%\pft3.tmp\extensions\scripts\ssl.lua
- %TEMP%\pft3.tmp\extensions\scripts\ToTypes.lua
- %TEMP%\pft3.tmp\extensions\scripts\Utility.lua
- %TEMP%\pft3.tmp\extensions\scripts\XmlToLua.lua
- %TEMP%\pft3.tmp\extensions\scripts\socket\tp.lua
- %TEMP%\pft3.tmp\extensions\scripts\socket.lua
- %ALLUSERSPROFILE%\Start Menu\Programs\Kaseya\Kaseya Agent.lnk
- %TEMP%\ext2.tmp
- %TEMP%\pft3.tmp\pftw1.pkg
- '%TEMP%\KAgentSilent.exe' /s /a /k /g TRWNT952407547840411 /l "%TEMP%\KASetup.log" /v "1"
- '%TEMP%\pft3.tmp\KASetup.exe' /k /g TRWNT952407547840411 /l "%TEMP%\KASetup.log" /v "1" /s