Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost.exe' = '%APPDATA%\svchost.exe.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\update store.lnk
- <SYSTEM32>\tasks\svchost.exe-8593
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\svchost.exe.exe
- %APPDATA%\svchost.exe.exe
- '62.#0.227.2':5463
- 'ip##pi.com':80
- '62.#0.227.2':5460
- '62.#0.227.2':5461
- http://ip##pi.com/json/
- '62.#0.227.2':5463
- '62.#0.227.2':5460
- '62.#0.227.2':5461
- DNS ASK ip##pi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command " $action = New-ScheduledTaskAction -Execute '%APPDATA%\svchost.exe.exe' $t...
- '<SYSTEM32>\cmd.exe' powershell -C "Add-MpPreference -ExclusionExtension '.exe' -EA 0" (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command " $action = New-ScheduledTaskAction -Execute '%APPDATA%\svchost.exe.exe' $t... (со скрытым окном)