Техническая информация
- [HKLM\Software\Classes\Counsellor\Shell\Open\Command] '' = 'wscript.exe //E:vbscript "%1"'
- <SYSTEM32>\lsass.exe
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- %TEMP%\upgrader.exe
- %TEMP%\457beb24-71ec-1185-e094-f5a38167d065.bat
- nul
- %WINDIR%\temp\5d02eb234fb7020285b02c67f7b9a6d5.rhh
- %APPDATA%\microsoft\windows\start menu\programs\otleotaueoehiitniaw tools upgrader.rhh
- %TEMP%\upgrader.exe
- '16#.#4.97.90':443
- '16#.#4.97.90':1443
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%TEMP%\upgrader.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\457beb24-71ec-1185-e094-f5a38167d065.bat" " (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\cmd.exe' /c subst I: "%APPDATA%\Microsoft\Windows\Start Menu\Programs"
- '<SYSTEM32>\subst.exe' I: "%APPDATA%\Microsoft\Windows\Start Menu\Programs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online (со скрытым окном)