Техническая информация
- <SYSTEM32>\tasks\windows_launcher
- %ALLUSERSPROFILE%\msosecurity\stream.exe
- %ALLUSERSPROFILE%\microsoft\gruz.crp
- %ALLUSERSPROFILE%\msosecurity\runtime-service.exe
- %ALLUSERSPROFILE%\msosecurity\stream.exe
- '%ALLUSERSPROFILE%\msosecurity\stream.exe'
- '%ALLUSERSPROFILE%\msosecurity\stream.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C schtasks /create /tn \Windows_launcher /tr %ALLUSERSPROFILE%\MSOSecurity\Stream.exe /st 00:00 /du 9999:59 /sc once /ri 1 /f
- '<SYSTEM32>\schtasks.exe' /create /tn \Windows_launcher /tr %ALLUSERSPROFILE%\MSOSecurity\Stream.exe /st 00:00 /du 9999:59 /sc once /ri 1 /f
- '<SYSTEM32>\taskeng.exe' {561EF5AC-17F7-4DBA-A24E-4D0857946FF8} S-1-5-21-1238866942-1249195528-555854008-1000:bsmavoeni\user:Interactive:[1]