Техническая информация
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\spoolsv
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\csrss
- %ProgramFiles%\luconfig\iexplore.exe
- %ProgramFiles%\luconfig\9db6e019d4f04ef534d0f91b3462d805c40e9d20
- <SYSTEM32>\mstsc\spoolsv.exe
- <SYSTEM32>\mstsc\f3b6ecef712a24f33798f5d2fb3790c3d9b894c4
- %ProgramFiles%\wsm\wininit.exe
- %ProgramFiles%\wsm\560854153607923c4c5f107085a7db67be01f252
- %ProgramFiles(x86)%\internet explorer\iexplore\iexplore.exe
- %ProgramFiles(x86)%\internet explorer\iexplore\9db6e019d4f04ef534d0f91b3462d805c40e9d20
- <Текущая директория>\spoolsv.exe
- <Текущая директория>\f3b6ecef712a24f33798f5d2fb3790c3d9b894c4
- %WINDIR%\branding\shellbrd\csrss.exe
- %WINDIR%\branding\shellbrd\886983d96e3d3e31032c679b2d4ea91b6c05afef
- 'cc####8.tmweb.ru':80
- 'ip##fo.io':443
- http://cc####8.tmweb.ru/PhpsecurePacketservergenerator.php?9j####################################################################################################################################...
- DNS ASK cc####8.tmweb.ru
- DNS ASK ip##fo.io
- '%WINDIR%\branding\shellbrd\csrss.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles%\LuConfig\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsv" /sc ONLOGON /tr "'<SYSTEM32>\mstsc\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'%ProgramFiles%\wsm\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Internet Explorer\iexplore\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsv" /sc ONLOGON /tr "'<Текущая директория>\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc ONLOGON /tr "'%WINDIR%\Branding\ShellBrd\csrss.exe'" /rl HIGHEST /f