Техническая информация
- <SYSTEM32>\tasks\avast security
- %APPDATA%\mirc\avast security.exe
- %TEMP%\tmp9f89.vbs
- %APPDATA%\mirc\avast security.exe
- %TEMP%\tmp9f89.vbs
- '45.##.156.41':27941
- http://45.##.156.41:27941/i via 45.##.156.41
- '%APPDATA%\mirc\avast security.exe'
- '<SYSTEM32>\cscript.exe' //nologo "%TEMP%\tmp9F89.vbs"
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\mIRC\Avast security.exe"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c @echo off & echo const TriggerTypeLogon=9 : const ActionTypeExecutable=0 : const TASK_LOGON_INTERACTIVE_TOKEN=3 : const createOrUpdateTask=6 : Set service=CreateObject("Schedule.Service") : ...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%APPDATA%\mIRC\Avast security.exe"
- '<SYSTEM32>\cmd.exe' /c @echo off & echo const TriggerTypeLogon=9 : const ActionTypeExecutable=0 : const TASK_LOGON_INTERACTIVE_TOKEN=3 : const createOrUpdateTask=6 : Set service=CreateObject("Schedule.Service") : ...