Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Update services' = '"<SYSTEM32>\wscript.exe" "%LOCALAPPDATA%\Gnome\core_stablity_report.vbs"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Send reports' = '"<SYSTEM32>\wscript.exe" "%LOCALAPPDATA%\Gnome\utility_report.vbs"'
- <SYSTEM32>\tasks\yandex search service\update services
- <SYSTEM32>\tasks\yandex search service\send reports
- %LOCALAPPDATA%\reports\core_stablity_report.vbs
- %LOCALAPPDATA%\gnome\core_stablity_report.vbs
- %LOCALAPPDATA%\reports\utility_report.vbs
- %LOCALAPPDATA%\gnome\utility_report.vbs
- %LOCALAPPDATA%\reports\core_stablity_report.vbs
- %LOCALAPPDATA%\gnome\core_stablity_report.vbs
- %LOCALAPPDATA%\reports\utility_report.vbs
- %LOCALAPPDATA%\gnome\utility_report.vbs
- 'di##ord.com':443
- 'di##ord.com':443
- DNS ASK di##ord.com
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Yandex Search Service\Update services" /tr "%LOCALAPPDATA%\Reports\core_stablity_report.vbs" /sc minute /mo 60 /f (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Yandex Search Service\Send reports" /tr "%LOCALAPPDATA%\Reports\utility_report.vbs" /sc minute /mo 60 /f (со скрытым окном)