Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '"%APPDATA%\svchost.exe"'
- <SYSTEM32>\tasks\svchost
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- %APPDATA%\svchost.exe
- %TEMP%\tmp7fab.tmp.bat
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<Имя файла>.exe.log
- nul
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\svchost.exe.log
- %APPDATA%\mydata\datalogs.conf
- '13#.#01.18.225':4449
- '%APPDATA%\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"%APPDATA%\svchost.exe"' & exit (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\tmp7FAB.tmp.bat""
- '%WINDIR%\syswow64\timeout.exe' 3
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc onlogon /rl highest /tn "svchost" /tr '"%APPDATA%\svchost.exe"'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'