Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OneDrive' = '%HOMEPATH%\Desktop\OneDrive.exe'
- <SYSTEM32>\tasks\onedrive
- %APPDATA%\microsoft\windows\start menu\programs\startup\onedrive.lnk
- [HKLM\SYSTEM\CurrentControlSet\Services\keyboard] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\keyboard] 'ImagePath' = '<SYSTEM32>\keyboard.exe'
- 'keyboard' <SYSTEM32>\keyboard.exe
- %TEMP%\microsoft\ajdhelf9.txt
- %TEMP%\onedrive.exe
- %HOMEPATH%\desktop\onedrive.exe
- %APPDATA%\onedrive.exe
- <SYSTEM32>\keyboard.exe
- %TEMP%\onedrive.exe
- %HOMEPATH%\desktop\onedrive.exe
- <SYSTEM32>\keyboard.exe
- DNS ASK ev###.ddns.net
- '<SYSTEM32>\cmd.exe' /c SCHTASKS /CREATE /TN OneDrive /TR "%TEMP%\OneDrive.exe" /SC ONSTART /RU "SYSTEM" /RL HIGHEST /F
- '<SYSTEM32>\schtasks.exe' /CREATE /TN OneDrive /TR "%TEMP%\OneDrive.exe" /SC ONSTART /RU "SYSTEM" /RL HIGHEST /F
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "%TEMP%\OneDrive.exe"
- '<SYSTEM32>\attrib.exe' +s +h "%TEMP%\OneDrive.exe"
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "%HOMEPATH%\Desktop\OneDrive.exe"
- '<SYSTEM32>\attrib.exe' +s +h "%HOMEPATH%\Desktop\OneDrive.exe"
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "<SYSTEM32>\keyboard.exe"
- '<SYSTEM32>\attrib.exe' +s +h "<SYSTEM32>\keyboard.exe"