Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'ExtreamFanV5' = '%LOCALAPPDATA%\ExtreamFanV5\ExtreamFanV5.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\powerexpertnt.lnk
- <SYSTEM32>\tasks\wintrackersp hr
- <SYSTEM32>\tasks\wintrackersp lg
- %LOCALAPPDATA%\extreamfanv5\extreamfanv5.exe
- %TEMP%\powerexpertnt\powerexpertnt.exe
- %ALLUSERSPROFILE%\wintrackersp\wintrackersp.exe
- %TEMP%\tmpstlpopstart\stlmapfrog
- '5.##.66.10':50505
- '5.##.66.10':50505
- '%WINDIR%\syswow64\schtasks.exe' /create /f /RU "user" /tr "%ALLUSERSPROFILE%\WinTrackerSP\WinTrackerSP.exe" /tn "WinTrackerSP HR" /sc HOURLY /rl HIGHEST
- '%WINDIR%\syswow64\schtasks.exe' /create /f /RU "user" /tr "%ALLUSERSPROFILE%\WinTrackerSP\WinTrackerSP.exe" /tn "WinTrackerSP LG" /sc ONLOGON /rl HIGHEST