Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ProgramFiles%\qhwscsvc\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"%ALLUSERSPROFILE%\Microsoft\User Account Pictures\Default Pictures\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"%ALLUSERSPROFILE%\Favorites\csrss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"%ProgramFiles(x86)%\Mozilla Firefox\gmp-clearkey\0.1\wininit.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '<Имя файла>' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'smss' = '"C:\Far2\PluginSDK\Headers.pas\smss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\csrss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ALLUSERSPROFILE%\Mozilla\logs\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"%ALLUSERSPROFILE%\Microsoft Help\explorer.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"C:\Far2\Documentation\eng\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'WUDFHost' = '"%ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\WUDFHost.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'winlogon' = '"%ProgramFiles(x86)%\Opera\Assets\winlogon.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"C:\Documents and Settings\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\iexplore.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'System' = '"%ProgramFiles(x86)%\Internet Explorer\MUI\0409\System.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ProgramFiles%\qhwscsvc\firefox.exe", "%ProgramFiles%\CavUMAS\iexplore.exe", "C:\MSOCache\All Users\{901...
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'mdm' = '"C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\mdm.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ProgramFiles%\qhwscsvc\firefox.exe", "%ProgramFiles%\CavUMAS\iexplore.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"%ProgramFiles%\CavUMAS\iexplore.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ProgramFiles%\qhwscsvc\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\totalcmd\LANGUAGE\csrss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Idle' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\Idle.exe"'
- <SYSTEM32>\tasks\uqzmfirefox
- <SYSTEM32>\tasks\txjk<Имя файла>
- <SYSTEM32>\tasks\d2gi<Имя файла>
- <SYSTEM32>\tasks\smss
- <SYSTEM32>\tasks\by7nsmss
- <SYSTEM32>\tasks\a4ctsmss
- <SYSTEM32>\tasks\<Имя файла>
- <SYSTEM32>\tasks\4ehlsmss
- <SYSTEM32>\tasks\hs45csrss
- <SYSTEM32>\tasks\s596csrss
- <SYSTEM32>\tasks\nrhjcsrss
- <SYSTEM32>\tasks\n0nyfirefox
- <SYSTEM32>\tasks\1mujfirefox
- <SYSTEM32>\tasks\ujvwfirefox
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\veo0wininit
- <SYSTEM32>\tasks\nxfiidle
- <SYSTEM32>\tasks\8p54idle
- <SYSTEM32>\tasks\sjbzcsrss
- <SYSTEM32>\tasks\9vt4csrss
- <SYSTEM32>\tasks\bou2csrss
- <SYSTEM32>\tasks\audiodg
- <SYSTEM32>\tasks\explorer
- <SYSTEM32>\tasks\6elp<Имя файла>
- <SYSTEM32>\tasks\zl4jaudiodg
- <SYSTEM32>\tasks\wfemcsrss
- <SYSTEM32>\tasks\fxxrcsrss
- <SYSTEM32>\tasks\looxcsrss
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\ae1fwininit
- <SYSTEM32>\tasks\m28yaudiodg
- <SYSTEM32>\tasks\mgpwwininit
- <SYSTEM32>\tasks\x9ieexplorer
- <SYSTEM32>\tasks\qynhexplorer
- <SYSTEM32>\tasks\deiiexplorer
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\xwhafirefox
- <SYSTEM32>\tasks\mw30firefox
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\bickiexplore
- <SYSTEM32>\tasks\rmbyiexplore
- <SYSTEM32>\tasks\qrnkidle
- <SYSTEM32>\tasks\4d1hiexplore
- <SYSTEM32>\tasks\system
- <SYSTEM32>\tasks\2vqkmdm
- <SYSTEM32>\tasks\ygvrmdm
- <SYSTEM32>\tasks\mdm
- <SYSTEM32>\tasks\anu9system
- <SYSTEM32>\tasks\sroxsystem
- <SYSTEM32>\tasks\yud1mdm
- <SYSTEM32>\tasks\ljaeaudiodg
- <SYSTEM32>\tasks\stlpiexplore
- <SYSTEM32>\tasks\4yigfirefox
- <SYSTEM32>\tasks\bdpiiexplore
- <SYSTEM32>\tasks\j1u7firefox
- <SYSTEM32>\tasks\qjj7firefox
- <SYSTEM32>\tasks\cexofirefox
- <SYSTEM32>\tasks\wudfhost
- <SYSTEM32>\tasks\s7b5wudfhost
- <SYSTEM32>\tasks\zklmiexplore
- <SYSTEM32>\tasks\0uf5wudfhost
- <SYSTEM32>\tasks\zbzwsystem
- <SYSTEM32>\tasks\qts2winlogon
- <SYSTEM32>\tasks\jydkwinlogon
- <SYSTEM32>\tasks\aagswinlogon
- <SYSTEM32>\tasks\k7f1firefox
- <SYSTEM32>\tasks\xyuefirefox
- <SYSTEM32>\tasks\opq9wudfhost
- <SYSTEM32>\tasks\idle
- %ProgramFiles%\qhwscsvc\firefox.exe
- %ALLUSERSPROFILE%\microsoft help\rcx871e.tmp
- C:\far2\documentation\eng\rcx846e.tmp
- C:\far2\documentation\eng\rcx83e1.tmp
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcx8151.tmp
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcx80c3.tmp
- %ProgramFiles(x86)%\opera\assets\rcx7e33.tmp
- %ProgramFiles(x86)%\opera\assets\rcx7da6.tmp
- %ALLUSERSPROFILE%\mozilla\logs\rcx8a3b.tmp
- %ALLUSERSPROFILE%\microsoft help\rcx87ab.tmp
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\rcx77e8.tmp
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\rcx775b.tmp
- %ProgramFiles(x86)%\internet explorer\mui\0409\rcx74bb.tmp
- %ProgramFiles(x86)%\internet explorer\mui\0409\rcx742e.tmp
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx719d.tmp
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx7110.tmp
- %ProgramFiles%\cavumas\rcx6e80.tmp
- C:\documents and settings\rcx7b15.tmp
- %ALLUSERSPROFILE%\mozilla\logs\firefox.exe
- %ALLUSERSPROFILE%\mozilla\logs\rcx8ac9.tmp
- %TEMP%\vtp5baf90x.bat
- %TEMP%\ofebvuh8cq
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxa3e4.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxa338.tmp
- C:\totalcmd\language\rcxa0a8.tmp
- C:\totalcmd\language\rcxa01a.tmp
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\rcx9d8a.tmp
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\rcx9cfd.tmp
- %ALLUSERSPROFILE%\favorites\rcx9a6c.tmp
- %ALLUSERSPROFILE%\favorites\rcx99df.tmp
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\rcx974f.tmp
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\rcx96c1.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcx9431.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcx93a4.tmp
- C:\far2\pluginsdk\headers.pas\rcx9113.tmp
- C:\far2\pluginsdk\headers.pas\rcx9076.tmp
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx8de6.tmp
- %ProgramFiles%\cavumas\rcx6df2.tmp
- C:\documents and settings\rcx7a78.tmp
- %ProgramFiles%\qhwscsvc\rcx6b62.tmp
- %ProgramFiles%\qhwscsvc\rcx6ab6.tmp
- <Текущая директория>\rcx6893.tmp
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\9db6e019d4f04e
- C:\far2\documentation\eng\firefox.exe
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\480b7989c529f6
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\wudfhost.exe
- %ProgramFiles(x86)%\opera\assets\cc11b995f2a76d
- %ProgramFiles(x86)%\opera\assets\winlogon.exe
- C:\documents and settings\0fc223bdacedc3
- C:\documents and settings\firefox.exe
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\iexplore.exe
- %ALLUSERSPROFILE%\microsoft help\explorer.exe
- %ProgramFiles(x86)%\internet explorer\mui\0409\27d1bcfc3c54e0
- %ProgramFiles(x86)%\internet explorer\mui\0409\system.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\559fba5f8e4410
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\mdm.exe
- %ProgramFiles%\cavumas\9db6e019d4f04e
- %ProgramFiles%\cavumas\iexplore.exe
- %ProgramFiles%\qhwscsvc\0fc223bdacedc3
- nul
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx8d59.tmp
- %ALLUSERSPROFILE%\microsoft help\7a0fd90576e088
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\csrss.exe
- C:\far2\documentation\eng\0fc223bdacedc3
- <Текущая директория>\rcx6853.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\6ccacd8608530f
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\idle.exe
- C:\totalcmd\language\886983d96e3d3e
- C:\totalcmd\language\csrss.exe
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\42af1c969fbb7b
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\audiodg.exe
- %ALLUSERSPROFILE%\favorites\886983d96e3d3e
- %ALLUSERSPROFILE%\favorites\csrss.exe
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\56085415360792
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\wininit.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\36b64fed840ba1
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe
- C:\far2\pluginsdk\headers.pas\69ddcba757bf72
- C:\far2\pluginsdk\headers.pas\smss.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\886983d96e3d3e
- %ALLUSERSPROFILE%\mozilla\logs\0fc223bdacedc3
- %TEMP%\tmp1351.tmp
- <Полный путь к файлу>
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\audiodg.exe
- %ALLUSERSPROFILE%\favorites\csrss.exe
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\wininit.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe
- C:\far2\pluginsdk\headers.pas\smss.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\csrss.exe
- %ALLUSERSPROFILE%\mozilla\logs\firefox.exe
- %ALLUSERSPROFILE%\microsoft help\explorer.exe
- C:\far2\documentation\eng\firefox.exe
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\wudfhost.exe
- %ProgramFiles(x86)%\opera\assets\winlogon.exe
- C:\documents and settings\firefox.exe
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\iexplore.exe
- %ProgramFiles(x86)%\internet explorer\mui\0409\system.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\mdm.exe
- %ProgramFiles%\cavumas\iexplore.exe
- %ProgramFiles%\qhwscsvc\firefox.exe
- C:\totalcmd\language\csrss.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\idle.exe
- %TEMP%\ofebvuh8cq
- <Текущая директория>\rcx6893.tmp в <Полный путь к файлу>
- %ALLUSERSPROFILE%\mozilla\logs\rcx8a3b.tmp в %ALLUSERSPROFILE%\mozilla\logs\firefox.exe
- %ALLUSERSPROFILE%\mozilla\logs\rcx8ac9.tmp в %ALLUSERSPROFILE%\mozilla\logs\firefox.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx8d59.tmp в C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\csrss.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx8de6.tmp в C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\csrss.exe
- C:\far2\pluginsdk\headers.pas\rcx9076.tmp в C:\far2\pluginsdk\headers.pas\smss.exe
- C:\far2\pluginsdk\headers.pas\rcx9113.tmp в C:\far2\pluginsdk\headers.pas\smss.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcx93a4.tmp в C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\rcx96c1.tmp в %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\wininit.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxa338.tmp в C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\idle.exe
- %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\rcx974f.tmp в %ProgramFiles(x86)%\mozilla firefox\gmp-clearkey\0.1\wininit.exe
- %ALLUSERSPROFILE%\favorites\rcx99df.tmp в %ALLUSERSPROFILE%\favorites\csrss.exe
- %ALLUSERSPROFILE%\favorites\rcx9a6c.tmp в %ALLUSERSPROFILE%\favorites\csrss.exe
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\rcx9cfd.tmp в %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\audiodg.exe
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\rcx9d8a.tmp в %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\audiodg.exe
- C:\totalcmd\language\rcxa01a.tmp в C:\totalcmd\language\csrss.exe
- C:\totalcmd\language\rcxa0a8.tmp в C:\totalcmd\language\csrss.exe
- %ALLUSERSPROFILE%\microsoft help\rcx87ab.tmp в %ALLUSERSPROFILE%\microsoft help\explorer.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcx9431.tmp в C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe
- %ALLUSERSPROFILE%\microsoft help\rcx871e.tmp в %ALLUSERSPROFILE%\microsoft help\explorer.exe
- %ProgramFiles(x86)%\internet explorer\mui\0409\rcx74bb.tmp в %ProgramFiles(x86)%\internet explorer\mui\0409\system.exe
- %ProgramFiles%\qhwscsvc\rcx6ab6.tmp в %ProgramFiles%\qhwscsvc\firefox.exe
- %ProgramFiles%\qhwscsvc\rcx6b62.tmp в %ProgramFiles%\qhwscsvc\firefox.exe
- %ProgramFiles%\cavumas\rcx6df2.tmp в %ProgramFiles%\cavumas\iexplore.exe
- %ProgramFiles%\cavumas\rcx6e80.tmp в %ProgramFiles%\cavumas\iexplore.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx7110.tmp в C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\mdm.exe
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\rcx719d.tmp в C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\mdm.exe
- %ProgramFiles(x86)%\internet explorer\mui\0409\rcx742e.tmp в %ProgramFiles(x86)%\internet explorer\mui\0409\system.exe
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\rcx775b.tmp в C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\iexplore.exe
- C:\far2\documentation\eng\rcx83e1.tmp в C:\far2\documentation\eng\firefox.exe
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\rcx77e8.tmp в C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\iexplore.exe
- C:\documents and settings\rcx7a78.tmp в C:\documents and settings\firefox.exe
- C:\documents and settings\rcx7b15.tmp в C:\documents and settings\firefox.exe
- %ProgramFiles(x86)%\opera\assets\rcx7da6.tmp в %ProgramFiles(x86)%\opera\assets\winlogon.exe
- %ProgramFiles(x86)%\opera\assets\rcx7e33.tmp в %ProgramFiles(x86)%\opera\assets\winlogon.exe
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcx80c3.tmp в %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\wudfhost.exe
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcx8151.tmp в %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\wudfhost.exe
- C:\far2\documentation\eng\rcx846e.tmp в C:\far2\documentation\eng\firefox.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxa3e4.tmp в C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\idle.exe
- 'h1#####.srv13.test-hf.su':80
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- http://h1#####.srv13.test-hf.su/externalphpLow.php?Wp############################################################################################################################################...
- http://h1#####.srv13.test-hf.su/externalphpLow.php?UE############################################################################################################################################...
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- DNS ASK h1#####.srv13.test-hf.su
- DNS ASK ip##fo.io
- DNS ASK ap#.##legram.org
- 'localhost':123
- '%ALLUSERSPROFILE%\favorites\csrss.exe'
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\VTp5BaF90X.bat"' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn "uQZmfirefox" /sc MINUTE /mo 14 /tr "'%ProgramFiles%\qhwscsvc\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<Имя файла>" /sc MINUTE /mo 14 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "6ELp<Имя файла>" /sc ONSTART /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "tXjK<Имя файла>" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "D2GI<Имя файла>" /sc MINUTE /mo 10 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<Имя файла>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc MINUTE /mo 13 /tr "'C:\Far2\PluginSDK\Headers.pas\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "By7Nsmss" /sc ONSTART /tr "'C:\Far2\PluginSDK\Headers.pas\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "a4Ctsmss" /sc ONLOGON /tr "'C:\Far2\PluginSDK\Headers.pas\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc MINUTE /mo 13 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mGpwwininit" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Mozilla Firefox\gmp-clearkey\0.1\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "hs45csrss" /sc ONSTART /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "S596csrss" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "nrhjcsrss" /sc MINUTE /mo 6 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 5 /tr "'%ALLUSERSPROFILE%\Mozilla\logs\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "n0nYfirefox" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Mozilla\logs\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "1Mujfirefox" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Mozilla\logs\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "4Ehlsmss" /sc MINUTE /mo 5 /tr "'C:\Far2\PluginSDK\Headers.pas\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "OPQ9WUDFHost" /sc MINUTE /mo 5 /tr "'%ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "ae1Fwininit" /sc ONSTART /tr "'%ProgramFiles(x86)%\Mozilla Firefox\gmp-clearkey\0.1\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Idle" /sc MINUTE /mo 9 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\Idle.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "QRnkIdle" /sc ONSTART /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "nXfIIdle" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "8P54Idle" /sc MINUTE /mo 9 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc MINUTE /mo 7 /tr "'C:\totalcmd\LANGUAGE\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "sJBzcsrss" /sc ONSTART /tr "'C:\totalcmd\LANGUAGE\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "9vt4csrss" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "uJVWfirefox" /sc MINUTE /mo 13 /tr "'%ALLUSERSPROFILE%\Mozilla\logs\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "veO0wininit" /sc MINUTE /mo 6 /tr "'%ProgramFiles(x86)%\Mozilla Firefox\gmp-clearkey\0.1\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lJAEaudiodg" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Microsoft\User Account Pictures\Default Pictures\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "M28yaudiodg" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Microsoft\User Account Pictures\Default Pictures\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "zL4jaudiodg" /sc MINUTE /mo 13 /tr "'%ALLUSERSPROFILE%\Microsoft\User Account Pictures\Default Pictures\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc MINUTE /mo 14 /tr "'%ALLUSERSPROFILE%\Favorites\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WfEmcsrss" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Favorites\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fXXrcsrss" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Favorites\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lOOxcsrss" /sc MINUTE /mo 12 /tr "'%ALLUSERSPROFILE%\Favorites\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc MINUTE /mo 5 /tr "'%ALLUSERSPROFILE%\Microsoft\User Account Pictures\Default Pictures\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc MINUTE /mo 7 /tr "'%ProgramFiles(x86)%\Mozilla Firefox\gmp-clearkey\0.1\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc MINUTE /mo 9 /tr "'%ALLUSERSPROFILE%\Microsoft Help\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "X9Ieexplorer" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Microsoft Help\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "QYnHexplorer" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Microsoft Help\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Yud1mdm" /sc MINUTE /mo 6 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "System" /sc MINUTE /mo 5 /tr "'%ProgramFiles(x86)%\Internet Explorer\MUI\0409\System.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "zBzwSystem" /sc ONSTART /tr "'%ProgramFiles(x86)%\Internet Explorer\MUI\0409\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SRoxSystem" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Internet Explorer\MUI\0409\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Anu9System" /sc MINUTE /mo 12 /tr "'%ProgramFiles(x86)%\Internet Explorer\MUI\0409\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdm" /sc MINUTE /mo 5 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\mdm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "YGvrmdm" /sc ONSTART /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\VTp5BaF90X.bat"
- '<SYSTEM32>\schtasks.exe' /create /tn "Bdpiiexplore" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc MINUTE /mo 6 /tr "'%ProgramFiles%\CavUMAS\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "4d1Hiexplore" /sc ONSTART /tr "'%ProgramFiles%\CavUMAS\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "rmbyiexplore" /sc ONLOGON /tr "'%ProgramFiles%\CavUMAS\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "bICKiexplore" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\CavUMAS\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 14 /tr "'%ProgramFiles%\qhwscsvc\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "MW30firefox" /sc ONSTART /tr "'%ProgramFiles%\qhwscsvc\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "xWhafirefox" /sc ONLOGON /tr "'%ProgramFiles%\qhwscsvc\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "2VQKmdm" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "BoU2csrss" /sc MINUTE /mo 8 /tr "'C:\totalcmd\LANGUAGE\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "zKlmiexplore" /sc ONSTART /tr "'C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "XyuEfirefox" /sc ONLOGON /tr "'C:\Documents and Settings\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc MINUTE /mo 14 /tr "'C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dEIIexplorer" /sc MINUTE /mo 5 /tr "'%ALLUSERSPROFILE%\Microsoft Help\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 8 /tr "'C:\Far2\Documentation\eng\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "j1u7firefox" /sc ONSTART /tr "'C:\Far2\Documentation\eng\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "QJj7firefox" /sc ONLOGON /tr "'C:\Far2\Documentation\eng\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "ceXofirefox" /sc MINUTE /mo 7 /tr "'C:\Far2\Documentation\eng\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHost" /sc MINUTE /mo 9 /tr "'%ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\WUDFHost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "4Yigfirefox" /sc MINUTE /mo 13 /tr "'C:\Documents and Settings\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "s7B5WUDFHost" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "STlpiexplore" /sc MINUTE /mo 14 /tr "'C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc MINUTE /mo 12 /tr "'%ProgramFiles(x86)%\Opera\Assets\winlogon.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "QTS2winlogon" /sc ONSTART /tr "'%ProgramFiles(x86)%\Opera\Assets\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "jyDkwinlogon" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Opera\Assets\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "AAGswinlogon" /sc MINUTE /mo 8 /tr "'%ProgramFiles(x86)%\Opera\Assets\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 7 /tr "'C:\Documents and Settings\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "K7F1firefox" /sc ONSTART /tr "'C:\Documents and Settings\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "0uF5WUDFHost" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2