Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdateSvc' = 'powershell -NoP -W H -Exec Bypass -File "%APPDATA%\windows_update.ps1"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'WindowsUpdateSvc' = 'powershell -NoP -W H -Exec Bypass -File "%APPDATA%\windows_update.ps1"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsupdateservice.url
- %TEMP%\hjynmfth.2zh.ps1
- %TEMP%\chrome_1425263093.db
- %TEMP%\wk50xhr5\wk50xhr5.0.cs
- %TEMP%\wk50xhr5\wk50xhr5.cmdline
- %TEMP%\wk50xhr5\wk50xhr5.out
- %TEMP%\chrome_1425263093.db
- %TEMP%\wk50xhr5\wk50xhr5.0.cs
- %TEMP%\wk50xhr5\wk50xhr5.cmdline
- %TEMP%\wk50xhr5\wk50xhr5.out
- %TEMP%\hjynmfth.2zh.ps1
- 'localhost':5000
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -W H -Exec Bypass -File "%TEMP%\hjynmfth.2zh.ps1"
- '<SYSTEM32>\netsh.exe' wlan show profiles
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\wk50xhr5\wk50xhr5.cmdline" (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Version 5.1 -s -NoLogo -NoProfile