Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\vitrmuukev.url
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\notepad.exe
- iexplore.exe
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\699c4b9cdebca7aaea5193cae8a50098_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %ALLUSERSPROFILE%\lkbnmtfjgl\csrss.exe
- %ALLUSERSPROFILE%\lkbnmtfjgl\e9c1286a28_3.1.0
- %ALLUSERSPROFILE%\lkbnmtfjgl\cfgi
- %ALLUSERSPROFILE%\lkbnmtfjgl\cfg
- %ALLUSERSPROFILE%\lkbnmtfjgl\csrss
- %ALLUSERSPROFILE%\lkbnmtfjgl\r.vbs
- %ALLUSERSPROFILE%\lkbnmtfjgl\csrss.exe
- %ALLUSERSPROFILE%\lkbnmtfjgl\r.vbs
- %ALLUSERSPROFILE%\lkbnmtfjgl\csrss.exe
- %ALLUSERSPROFILE%\lkbnmtfjgl\r.vbs
- '45.##4.225.135':80
- 'po##.#upportxmr.com':3333
- http://45.##4.225.135/notepad.exe
- DNS ASK po##.#upportxmr.com
- '%WINDIR%\notepad.exe' -c "%ALLUSERSPROFILE%\LKBNMTFJgl\cfg"
- '%WINDIR%\syswow64\cmd.exe' /C WScript "%ALLUSERSPROFILE%\LKBNMTFJgl\r.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%ALLUSERSPROFILE%\LKBNMTFJgl\r.vbs"
- '%WINDIR%\notepad.exe' -c "%ALLUSERSPROFILE%\LKBNMTFJgl\cfgi"