Техническая информация
- <SYSTEM32>\tasks\comsurrogate
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %HOMEPATH%\documents\windowspowershell\dllhost.exe
- '19#.#35.91.190':80
- '46.#.19.252':80
- http://19#.#35.91.190/cr/text.txt
- http://46.#.19.252/gate.php?ty###################################
- '%HOMEPATH%\documents\windowspowershell\dllhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath C:\Users' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath C:\Users
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath C:\Users
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn COMSurrogate /st 00:00 /du 9999:59 /sc once /ri 1 /f /tr "%HOMEPATH%\Documents\WindowsPowerShell\dllhost.exe"