Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\Services\WmdmPmSp] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\WmdmPmSp] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\WmdmPmSp\Parameters] 'ServiceDll' = '<SYSTEM32>\WmdmPmSpex.dll'
- %TEMP%\mir.exe
- %WINDIR%\syswow64\wmdmpmspex.dll
- %WINDIR%\syswow64\wmdmpmspex.dll.reg
- %WINDIR%\syswow64\wmdmpmspex.cmd
- %TEMP%\~del!.bat
- %WINDIR%\syswow64\wmdmpmspex.dll
- %TEMP%\~del!.bat
- %TEMP%\mir.exe
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\mir.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\mir.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\WmdmPmSpex.cmd" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~DeL!.bAt' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\mir.exe"
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\WmdmPmSpex.cmd" "
- '%WINDIR%\syswow64\regedit.exe' /s WmdmPmSpex.dll.reg
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~DeL!.bAt