Техническая информация
- <SYSTEM32>\tasks\kl_autostart
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\Users\Public'
- %TEMP%\nswe689.tmp
- C:\users\public\documents\.ds_store
- C:\users\public\documents\cef_frame.dll
- C:\users\public\documents\latest.exe
- C:\users\public\documents\mesedge.exe
- %TEMP%\nsd11ee.tmp\system.dll
- %TEMP%\nsd11ee.tmp\modern-header.bmp
- %TEMP%\nsd11ee.tmp\modern-wizard.bmp
- %TEMP%\nsd11ee.tmp\nsdialogs.dll
- 'ks##5.com':443
- 'ks##5.com':443
- DNS ASK ks##5.com
- 'C:\users\public\documents\mesedge.exe'
- 'C:\users\public\documents\latest.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "KL_AutoStart" /tr "C:\Users\Public\Documents\mesedge.exe" /sc onlogon /rl highest /f
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\Users\Public' (со скрытым окном)