Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'DuckClientUpdate' = '"%APPDATA%\DuckApp\syshost.exe" -installed'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsupdate.vbs
- <SYSTEM32>\tasks\duckupdate
- <Текущая директория>\config.json
- %APPDATA%\duckapp\syshost.exe
- %APPDATA%\duckapp\config.json
- <Текущая директория>\config.json
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsupdate.vbs
- %APPDATA%\duckapp\config.json
- DNS ASK om####.ooguy.com
- '%APPDATA%\duckapp\syshost.exe' -installed
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn "DuckUpdate" /tr "\"%APPDATA%\DuckApp\syshost.exe\" -installed" /sc onlogon /f (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "DuckUpdate" /tr "\"%APPDATA%\DuckApp\syshost.exe\" -installed" /sc onlogon /f
- '%APPDATA%\duckapp\syshost.exe' -installed (со скрытым окном)