Техническая информация
- <SYSTEM32>\tasks\systemupdate
- <SYSTEM32>\tasks\winrun
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\noncrypt.exe
- %ALLUSERSPROFILE%\winsys.exe
- %TEMP%\systemdebug.exe
- '2n#.co':443
- '2n#.co':443
- DNS ASK 2n#.co
- ClassName: 'EDIT' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%TEMP%\noncrypt.exe'
- '%ALLUSERSPROFILE%\winsys.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WinRun /tr "C:/ProgramData/WinSys.exe" /sc minute /F' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn SystemUpdate /tr "%TEMP%\SystemDebug.exe" /sc hourly /F' (со скрытым окном)
- '%ALLUSERSPROFILE%\winsys.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WinRun /tr "C:/ProgramData/WinSys.exe" /sc minute /F
- '%WINDIR%\syswow64\schtasks.exe' /create /tn SystemUpdate /tr "%TEMP%\SystemDebug.exe" /sc hourly /F
- '<SYSTEM32>\taskeng.exe' {7A7EC39C-E7F1-468D-B329-1D088C6A45DD} S-1-5-21-1960123792-2022915161-3775307078-1001:auhmybdavv\user:Interactive:[1]