Техническая информация
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<SYSTEM32>\config\systemprofile\AppData\Roaming\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' <SYSTEM32>\config\systemprofile\AppData\Roaming\Google\Libs\WR64.sys
- <SYSTEM32>\conhost.exe
- %TEMP%\extrarar.exe
- %TEMP%\pw.txt
- %TEMP%\rar.rar
- %TEMP%\go.bat
- nul
- %TEMP%\chromekey.exe
- %TEMP%\installer.exe
- %TEMP%\go.bat
- %TEMP%\extrarar.exe
- %TEMP%\pw.txt
- %TEMP%\rar.rar
- DNS ASK xm#.#miners.com
- DNS ASK pa###bin.com
- '%TEMP%\extrarar.exe' x -o+ rar.rar -pna^C#a$lf38bSa1Rty*c0Ho#XmDRdK8tRWP6!PH%6E1Gzksd&x
- '%TEMP%\chromekey.exe'
- '%TEMP%\installer.exe'
- '%ProgramFiles%\google\chrome\updater.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\go.bat" > NUL"' (со скрытым окном)
- '%ProgramFiles%\google\chrome\updater.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\go.bat" > NUL"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"