Техническая информация
- <SYSTEM32>\tasks\createexplorershellunelevatedtask
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %TEMP%\bwra558.bat
- %TEMP%\bwra558.bat
- DNS ASK ap#.msn.com
- ClassName: '' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'ApplicationFrameWindow' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C ""%TEMP%\BWRA558.bat""
- '%WINDIR%\explorer.exe'
- '%WINDIR%\explorer.exe' /NoUACCheck
- '%WINDIR%\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe' -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc