Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windefender' = '%APPDATA%\Installed\windefender.exe'
- [<HKLM>\System\CurrentControlSet\Services\Windows Host Process] 'ImagePath' = '%APPDATA%\drv.sys'
- 'Windows Host Process' %APPDATA%\drv.sys
- %APPDATA%\ntkrnl
- %APPDATA%\installed\windefender.exe
- %APPDATA%\drv.sys
- %WINDIR%\temp\udd42aa.tmp
- %WINDIR%\temp\udd42aa.tmp
- DNS ASK ad####lasherup1.com
- DNS ASK ja###racle2.ru
- '%APPDATA%\installed\windefender.exe'