Техническая информация
- <SYSTEM32>\tasks\avast security
- %APPDATA%\qipguard\avast security.exe
- %TEMP%\tmpfb4f.vbs
- %APPDATA%\qipguard\avast security.exe
- %TEMP%\tmpfb4f.vbs
- '62.##4.41.141':27941
- http://62.###.41.141:27941/ via 62.##4.41.141
- '%APPDATA%\qipguard\avast security.exe'
- '<SYSTEM32>\cscript.exe' //nologo "%TEMP%\tmpFB4F.vbs"
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\QipGuard\Avast security.exe"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c @echo off & echo const TriggerTypeLogon=9 : const ActionTypeExecutable=0 : const TASK_LOGON_INTERACTIVE_TOKEN=3 : const createOrUpdateTask=6 : Set service=CreateObject("Schedule.Service") : ...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\QipGuard\Avast security.exe"
- '<SYSTEM32>\cmd.exe' /c @echo off & echo const TriggerTypeLogon=9 : const ActionTypeExecutable=0 : const TASK_LOGON_INTERACTIVE_TOKEN=3 : const createOrUpdateTask=6 : Set service=CreateObject("Schedule.Service") : ...