Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8Q1Q27K2-I686-I3VP-7P31-O0A0110232BK}] 'StubPath' = '"%APPDATA%\Install\Host.exe"'
- <SYSTEM32>\tasks\workfolders
- host.exe
- %APPDATA%\install\host.exe
- %HOMEPATH%\regsvr32\audioendpointbuilder.exe
- %APPDATA%\install\host.exe
- 'ca#.##lls-it.net':3360
- DNS ASK ca#.##lls-it.net
- '%APPDATA%\install\host.exe'
- '%HOMEPATH%\regsvr32\audioendpointbuilder.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WorkFolders /tr "%HOMEPATH%\regsvr32\AudioEndpointBuilder.exe" /sc minute /mo 1 /F' (со скрытым окном)
- '%HOMEPATH%\regsvr32\audioendpointbuilder.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WorkFolders /tr "%HOMEPATH%\regsvr32\AudioEndpointBuilder.exe" /sc minute /mo 1 /F
- '<SYSTEM32>\taskeng.exe' {6237CF4B-DCC8-4028-8C70-F79C8E1A1734} S-1-5-21-1960123792-2022915161-3775307078-1001:ttvhxyvcm\user:Interactive:[1]