Техническая информация
- <SYSTEM32>\tasks\dvatk
- mzdumpw.exe
- %TEMP%\ixp000.tmp\mzdumpw.exe
- %TEMP%\ixp000.tmp\hpgt.qys
- %TEMP%\ixp000.tmp\pxjowmv.dck
- %HOMEPATH%\mzdumpw.exe
- %APPDATA%\36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee\run.dat
- %HOMEPATH%\dvatk\hpgt.qys
- %HOMEPATH%\dvatk\mzdumpw.exe
- %HOMEPATH%\dvatk\pxjowmv.dck
- %HOMEPATH%\mzdumpw.exe
- %TEMP%\ixp000.tmp\hpgt.qys в %HOMEPATH%\dvatk\hpgt.qys
- %TEMP%\ixp000.tmp\mzdumpw.exe в %HOMEPATH%\dvatk\mzdumpw.exe
- %TEMP%\ixp000.tmp\pxjowmv.dck в %HOMEPATH%\dvatk\pxjowmv.dck
- 'bp#####tion.duckdns.org':3606
- DNS ASK bp#####tion.zapto.org
- DNS ASK bp#####tion.duckdns.org
- '%TEMP%\ixp000.tmp\mzdumpw.exe' hpgt.qys
- '%HOMEPATH%\mzdumpw.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 5 /tn dvatk /tr "%HOMEPATH%\dvatk\mzdumpw.exe %HOMEPATH%\dvatk\hpgt.qys"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 5 /tn dvatk /tr "%HOMEPATH%\dvatk\mzdumpw.exe %HOMEPATH%\dvatk\hpgt.qys"
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 5 /tn dvatk /tr "%HOMEPATH%\dvatk\mzdumpw.exe %HOMEPATH%\dvatk\hpgt.qys"