Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'EC478E28' = '%WINDIR%\EC478E28\svchsot.exe'
- %WINDIR%\temp\server.exe
- %WINDIR%\temp\äú²¿ºì¹·03-12.exe
- %WINDIR%\ec478e28\svchsot.exe
- ClassName: '' WindowName: ''
- '%WINDIR%\temp\äú²¿ºì¹·03-12.exe'
- '%WINDIR%\temp\server.exe'
- '%WINDIR%\syswow64\net.exe' start "Task Scheduler" (со скрытым окном)
- '%WINDIR%\syswow64\net1.exe' start "Task Scheduler"