Техническая информация
- <SYSTEM32>\tasks\pjevzdhcuulpzchtywsimulmzxjebkmbuusoslpoxmwrdpjjsitynhnlcvolbjivzoxcnlpfjcxoinuntumgzxgkxlggtbmabia
- C:\users\public\documents\sxgikdhicymyvsatwcyc.exe
- C:\users\default\appdata\roaming\mzlchxeazzceaduukmyrrtejqsmkcpsjzkkvyzlpvwigdckisfdtwmwmzlhqewcaahcswsqlpvvwbjhbaiwgqpixjumingkvaus.cmd
- C:\users\default\appdata\local\libxscore.bundle
- nul
- <SYSTEM32>\tasks\pjevzdhcuulpzchtywsimulmzxjebkmbuusoslpoxmwrdpjjsitynhnlcvolbjivzoxcnlpfjcxoinuntumgzxgkxlggtbmabia
- '60.##5.128.71':8080
- '60.##5.128.71':8080
- 'C:\users\public\documents\sxgikdhicymyvsatwcyc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c C:\\Users\\Default\\AppData\\Roaming\\MzlchxeAZZCEaDuUKmYRRTEjqSMKCPSjzkKvyZLPvwIGDckIsfdtwMWmZlHqeWCAAHCsWSQlpvvwbJHBaiwGQPiXJumiNGkvAuS.cmd (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c tasklist.exe | find /I "SXGIkdHiCymYVsAtwcYC.exe"
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\find.exe' /I "SXGIkdHiCymYVsAtwcYC.exe"
- '%WINDIR%\syswow64\choice.exe' /t 5 /d y /n