Техническая информация
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\lsass
- %TEMP%\build.vmp.sfx.exe
- %TEMP%\eset_internet_security_live_installer.exe
- %TEMP%\build.vmp.exe
- <SYSTEM32>\dsuiext\wininit.exe
- <SYSTEM32>\dsuiext\560854153607923c4c5f107085a7db67be01f252
- <SYSTEM32>\winrshost\winlogon.exe
- <SYSTEM32>\winrshost\cc11b995f2a76da408ea6a601e682e64743153ad
- <SYSTEM32>\odbcint\dwm.exe
- <SYSTEM32>\odbcint\6cb0b6c459d5d3455a3da700e713f2e2529862ff
- %WINDIR%\resources\0409\lsass.exe
- %WINDIR%\resources\0409\6203df4a6bafc7c328ee7f6f8ca0a8a838a8a1b9
- '21#.#09.196.79':80
- 'ip##fo.io':443
- http://21#.#09.196.79/lowauthdefault.php?LY######################################################################################################################################################...
- DNS ASK ip##fo.io
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\build.vmp.sfx.exe'
- '%TEMP%\build.vmp.exe'
- '%WINDIR%\resources\0409\lsass.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'<SYSTEM32>\dsuiext\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'<SYSTEM32>\winrshost\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'<SYSTEM32>\odbcint\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'%WINDIR%\Resources\0409\lsass.exe'" /rl HIGHEST /f