Техническая информация
- <SYSTEM32>\tasks\cofax
- '%TEMP%\oseebb9.tmp'
- %TEMP%\wd4sx.wmf
- %TEMP%\oseebb9.tmp
- %WINDIR%\temp\~f426.tmp
- %WINDIR%\temp\~f427.tmp
- %PROGRAMDATA%\confax\confax.exe
- %PROGRAMDATA%\confax\lbtserv.dll
- %WINDIR%\temp\~f426.tmp
- %WINDIR%\temp\~f427.tmp
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /tn "Cofax" /f' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 10 /tn "Cofax" /tr "%PROGRAMDATA%\Confax\confax.exe" /ru "system"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /tn "Cofax" /f
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 10 /tn "Cofax" /tr "%PROGRAMDATA%\Confax\confax.exe" /ru "system"
- '%WINDIR%\syswow64\schtasks.exe' /delete /tn "Cofax" /f
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 10 /tn "Cofax" /tr "%PROGRAMDATA%\Confax\confax.exe" /ru "system"