Техническая информация
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%ProgramFiles%\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' %ProgramFiles%\Google\Libs\WR64.sys
- <SYSTEM32>\conhost.exe
- %TEMP%\skinchanger.exe
- %TEMP%\setup.exe
- %TEMP%\vsdc7e0.tmp\install.log
- DNS ASK xm#.#miners.com
- DNS ASK pa###bin.com
- DNS ASK f0####85.xsph.ru
- '%TEMP%\skinchanger.exe'
- '%TEMP%\setup.exe'
- '%ProgramFiles%\google\chrome\updater.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAHkAeABkACMAPgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAHcAegB2ACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...' (со скрытым окном)
- '%TEMP%\skinchanger.exe' ' (со скрытым окном)
- '%TEMP%\setup.exe' ' (со скрытым окном)
- '%ProgramFiles%\google\chrome\updater.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAHkAeABkACMAPgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAHcAegB2ACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...