Техническая информация
- <SYSTEM32>\tasks\pjvsr
- poilolhe.exe
- %TEMP%\ixp000.tmp\poilolhe.exe
- %TEMP%\ixp000.tmp\giob.ztv
- %TEMP%\ixp000.tmp\gtfvc.nsf
- %HOMEPATH%\poilolhe.exe
- %HOMEPATH%\pjvsr\giob.ztv
- %HOMEPATH%\pjvsr\gtfvc.nsf
- %HOMEPATH%\pjvsr\poilolhe.exe
- %HOMEPATH%\poilolhe.exe
- %TEMP%\ixp000.tmp\giob.ztv в %HOMEPATH%\pjvsr\giob.ztv
- %TEMP%\ixp000.tmp\gtfvc.nsf в %HOMEPATH%\pjvsr\gtfvc.nsf
- %TEMP%\ixp000.tmp\poilolhe.exe в %HOMEPATH%\pjvsr\poilolhe.exe
- 'co###.ocitnetad.com':3360
- DNS ASK co###.ocitnetad.com
- '%TEMP%\ixp000.tmp\poilolhe.exe' giob.ztv
- '%HOMEPATH%\poilolhe.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 5 /tn pjvsr /tr "%HOMEPATH%\pjvsr\poilolhe.exe %HOMEPATH%\pjvsr\giob.ztv"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 5 /tn pjvsr /tr "%HOMEPATH%\pjvsr\poilolhe.exe %HOMEPATH%\pjvsr\giob.ztv"
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 5 /tn pjvsr /tr "%HOMEPATH%\pjvsr\poilolhe.exe %HOMEPATH%\pjvsr\giob.ztv"