Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DefenderSDK' = 'wscript %ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.vbs'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DefenderSDK' = 'wscript %ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.vbs'
- <SYSTEM32>\tasks\microsoft\windowsdefendersdk
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.vbs"
- %ALLUSERSPROFILE%\firefoxsdk\configregistersdk.ini
- %ALLUSERSPROFILE%\firefoxsdk\configregistersdk.vbs
- %ALLUSERSPROFILE%\firefoxsdk\configregistersdk.vbs
- %ALLUSERSPROFILE%\firefoxsdk\configregistersdk.ini
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -exec Bypass -nologo -noprofile -c iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String((get-content "%ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.ini"))));' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -exec Bypass -nologo -noprofile -c iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String((get-content "%ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.ini"))));
- '<SYSTEM32>\attrib.exe' +s +h %ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.vbs
- '<SYSTEM32>\attrib.exe' +s +h %ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.ini
- '<SYSTEM32>\schtasks.exe' /Create /RU system /SC ONLOGON /TN Microsoft\WindowsDefenderSDK /TR "wscript %ALLUSERSPROFILE%\FirefoxSDK\ConfigRegisterSDK.vbs" /F