Техническая информация
- <SYSTEM32>\tasks\ulqfofpcuv
- <SYSTEM32>\tasks\keyalgorithm
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionPath '%APPDATA%\IsCompleted\KeyAlgorithm.exe' -Force ; Add-MpPreference -ExclusionPath '%WINDIR%\Microsoft.NET\Framework64\v4...
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- %WINDIR%\temp\~temp.tmp
- %APPDATA%\iscompleted\keyalgorithm.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<Имя файла>.exe.log
- %APPDATA%\iscompleted\keyalgorithm.exe
- <SYSTEM32>\tasks\ulqfofpcuv
- DNS ASK fi#####.###tings.services.mozilla.com
- '%APPDATA%\iscompleted\keyalgorithm.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -NoProfile -Command "System.Collections.Generic.List`1[System.String]"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe' (со скрытым окном)