Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"C:\Documents and Settings\wininit.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dwm' = '"%ProgramFiles(x86)%\Opera\Assets\dwm.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\csrss.exe"'
- <SYSTEM32>\tasks\bbodarbbszctr
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\csrss
- %TEMP%\fajiczcj22cc8hmflecshcqem21kvq0p.exe
- %TEMP%\abggdy5ddsfqf0u7g1otfdscuewkhrnl.exe
- %ProgramFiles%\gsehynltxmyzu\bbodarbbszctr.exe
- C:\documents and settings\wininit.exe
- C:\documents and settings\560854153607923c4c5f107085a7db67be01f252
- %ProgramFiles(x86)%\opera\assets\dwm.exe
- %ProgramFiles(x86)%\opera\assets\6cb0b6c459d5d3455a3da700e713f2e2529862ff
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\csrss.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\886983d96e3d3e31032c679b2d4ea91b6c05afef
- %TEMP%\tmp23b8.tmp.bat
- nul
- %TEMP%\fajiczcj22cc8hmflecshcqem21kvq0p.exe
- '%TEMP%\fajiczcj22cc8hmflecshcqem21kvq0p.exe'
- '%TEMP%\abggdy5ddsfqf0u7g1otfdscuewkhrnl.exe'
- 'C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\csrss.exe'
- '%ProgramFiles%\gsehynltxmyzu\bbodarbbszctr.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "bbodarbbszctr" /tr '"%ProgramFiles%\gsehynltxmyzu\bbodarbbszctr.exe"' & exit' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "bbodarbbszctr" /tr '"%ProgramFiles%\gsehynltxmyzu\bbodarbbszctr.exe"' & exit
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn "bbodarbbszctr" /tr '"%ProgramFiles%\gsehynltxmyzu\bbodarbbszctr.exe"'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'C:\Documents and Settings\wininit.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Opera\Assets\dwm.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "csrss" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp23B8.tmp.bat""
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Get-MpPreference -verbose