Техническая информация
- <SYSTEM32>\tasks\svchostrutv
- <SYSTEM32>\conhost.exe
- %APPDATA%\google\chrome\updater.exe
- %TEMP%\ajgzafat.tmp
- %APPDATA%\google\libs\g.log
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#lxdpbxgh#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { schtasks...
- '%APPDATA%\google\chrome\updater.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#vpsgcpq#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([Syste...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#vpsgcpq#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([Syste...
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn svchostrutv /tr '%APPDATA%\Google\Chrome\updater.exe'
- '<SYSTEM32>\schtasks.exe' /run /tn svchostrutv
- '<SYSTEM32>\taskeng.exe' {34E10ECC-FA47-4E26-A8AF-B8381E3C6C57} S-1-5-21-3691498038-2086406363-2140527554-1000:cwwzxej\user:Interactive:[1]
- '<SYSTEM32>\cmd.exe' /c wmic PATH Win32_VideoController GET Name, VideoProcessor > "%APPDATA%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name, VideoProcessor
- '%APPDATA%\google\chrome\updater.exe' (со скрытым окном)