Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Updater' = 'wscript C:\Users\Public\Documents\conf.vbs'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Updater' = 'wscript C:\Users\Public\Documents\conf.vbs'
- <SYSTEM32>\tasks\updater
- '<SYSTEM32>\wscript.exe' c:\users\public\documents\conf.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -file C:\Users\Public\Documents\Updater.ps1
- C:\users\public\documents\updater.ps1
- C:\users\public\documents\conf.vbs
- C:\users\public\documents\updater.ps1
- C:\users\public\documents\conf.vbs
- '14#.#6.109.88':80
- '<SYSTEM32>\wscript.exe' c:\users\public\documents\conf.vbs' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -file C:\Users\Public\Documents\Updater.ps1' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' /automation -Embedding
- '<SYSTEM32>\schtasks.exe' /Create /RU system /SC ONLOGON /TN Updater /TR C:\Users\Public\Documents\conf.vbs /F
- '<SYSTEM32>\attrib.exe' +s +h C:\Users\public\documents\Updater.ps1
- '<SYSTEM32>\attrib.exe' +s +h C:\Users\public\documents\conf.vbs