Техническая информация
- <SYSTEM32>\tasks\securityhealthsystray
- %TEMP%\ofvygyxfrj.exe
- %TEMP%\zqyoyp.exe
- %APPDATA%\securityhealthsystray.exe
- %APPDATA%\microsoft\libs\sihost64.exe
- %APPDATA%\microsoft\libs\wr64.sys
- '34.##9.100.209':443
- '%TEMP%\ofvygyxfrj.exe'
- '%TEMP%\zqyoyp.exe'
- '%APPDATA%\microsoft\libs\sihost64.exe'
- '%APPDATA%\securityhealthsystray.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "SecurityHealthSystray" /tr '"%APPDATA%\SecurityHealthSystray.exe"' & exit (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn "SecurityHealthSystray" /tr '"%APPDATA%\SecurityHealthSystray.exe"'