Техническая информация
- <SYSTEM32>\tasks\vsuserconfig
- %LOCALAPPDATA%\microsoft\vsuserconfig\vsuserconfig.exe
- 'de##.#amorat.com':443
- DNS ASK de##.#amorat.com
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn VSUserconfig /tr %LOCALAPPDATA%\Microsoft\VSUserconfig\VSUserconfig.exe
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc onlogon /rl highest /tn VSUserconfig /tr %LOCALAPPDATA%\Microsoft\VSUserconfig\VSUserconfig.exe