Техническая информация
- <SYSTEM32>\tasks\svchost
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\Microsoft\Libs\WR64.sys'
- 'WinRing0_1_2_0' %APPDATA%\Microsoft\Libs\WR64.sys
- <SYSTEM32>\conhost.exe
- %TEMP%\thx.exe
- %WINDIR%\svchost.exe
- DNS ASK po##.#ashvault.pro
- '%TEMP%\thx.exe'
- '%WINDIR%\svchost.exe'
- '<SYSTEM32>\microsoft\libs\sihost64.exe'
- '<SYSTEM32>\microsoft\libs\sihost64.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath @($env:UserProfile,$env:AppData,$env:Temp,$env:SystemRoot,$env:HomeDrive,$env:SystemDrive) -Force" & powershell -Command "Add-MpPreferenc...
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\THX.exe"
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%WINDIR%\svchost.exe"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath @($env:UserProfile,$env:AppData,$env:Temp,$env:SystemRoot,$env:HomeDrive,$env:SystemDrive) -Force"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionExtension @('exe','dll') -Force"