Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SecurityHealthService' = '%APPDATA%\Microsoft\Windows\Themes\SecurityHealthService.exe'
- <SYSTEM32>\tasks\microsoft\windows\security\securityhealthservice
- Процесс app.exe, модуль ntdll.dll
- %TEMP%\2b1dc01d\app.exe
- %TEMP%\~cfg3910.tmp
- %APPDATA%\microsoft\windows\themes\securityhealthservice.exe
- %APPDATA%\microsoft\windows\themes\securityhealthservice.exe
- %TEMP%\~cfg3910.tmp
- '15#.#20.119.236':5023
- 'localhost':27042
- ClassName: 'SandboxieControlWndClass' WindowName: ''
- ClassName: 'Afx:400000:0' WindowName: ''
- '%TEMP%\2b1dc01d\app.exe'
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN "\Microsoft\Windows\Security\SecurityHealthService" /TR "\"%APPDATA%\Microsoft\Windows\Themes\SecurityHealthService.exe\"" /RL HIGHEST (со скрытым окном)
- '%TEMP%\2b1dc01d\app.exe' (со скрытым окном)