Техническая информация
- <SYSTEM32>\tasks\updates\kkeghw
- '%APPDATA%\oiuytresgdfghj,k.l.exe'
- oiuytresgdfghj,k.l.exe
- %APPDATA%\oiuytresgdfghj,k.l.exe
- %APPDATA%\kkeghw.exe
- %TEMP%\tmp69cd.tmp
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\oiuytresgdfghj,k.l.exe.log
- %APPDATA%\kkeghw.exe
- http://ba##e.xyz/saveme/sam.exe
- DNS ASK ba##e.xyz
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\KKeGhW" /XML "%TEMP%\tmp69CD.tmp"' (со скрытым окном)
- '%CommonProgramFiles(x86)%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\KKeGhW" /XML "%TEMP%\tmp69CD.tmp"