Техническая информация
- <SYSTEM32>\tasks\defendertool
- %TEMP%\temp1.exe
- %TEMP%\temp2.exe
- %APPDATA%\defendertool.exe
- %TEMP%\tmpe648.tmp.bat
- nul
- '%TEMP%\temp1.exe'
- '%TEMP%\temp2.exe'
- '%APPDATA%\defendertool.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "defendertool" /tr '"%APPDATA%\defendertool.exe"' & exit (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\tmpE648.tmp.bat""
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc onlogon /rl highest /tn "defendertool" /tr '"%APPDATA%\defendertool.exe"'
- '%WINDIR%\syswow64\timeout.exe' 3