Техническая информация
- <SYSTEM32>\tasks\nicosoft
- [<HKLM>\System\CurrentControlSet\Services\NsSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\NsSvc] 'ImagePath' = '<SYSTEM32>\nscd.exe'
- 'NsSvc' <SYSTEM32>\nscd.exe
- <SYSTEM32>\task.exe
- <SYSTEM32>\nscd.exe
- %WINDIR%\winring0x64.sys
- %WINDIR%\java.exe
- 'ni###oft.org':80
- 'xm#.#2pool.com':13531
- 'xm#.#2pool.com':13531
- DNS ASK ni###oft.org
- DNS ASK xm#.#2pool.com
- '<SYSTEM32>\task.exe' -s
- '<SYSTEM32>\nscd.exe'
- '%WINDIR%\java.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "NicoSoft" /ru system /tr "<SYSTEM32>\task.exe -s"' (со скрытым окном)
- '<SYSTEM32>\task.exe' -s' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "NicoSoft" /ru system /tr "<SYSTEM32>\task.exe -s"