Техническая информация
- [\REGISTRY\USER\S-1-5-21-1238866942-1249195528-555854008-1000\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"%WINDIR%\rss\csrss.exe"'
- <SYSTEM32>\tasks\csrss
- [HKLM\System\CurrentControlSet\Services\VBoxWddm] 'ImagePath' = 'VBoxWddm'
- [HKLM\System\CurrentControlSet\Services\VBoxSF] 'ImagePath' = 'VBoxSF'
- [HKLM\System\CurrentControlSet\Services\VBoxMouse] 'ImagePath' = 'VBoxMouse'
- [HKLM\System\CurrentControlSet\Services\VBoxGuest] 'ImagePath' = 'VBoxGuest'
- [HKLM\System\CurrentControlSet\Services\VBoxService] 'ImagePath' = 'VBoxService'
- [HKLM\System\CurrentControlSet\Services\VBoxVideo] 'ImagePath' = 'VBoxVideo'
- [HKLM\System\CurrentControlSet\Services\VBoxDrv] 'ImagePath' = '<DRIVERS>\VBoxDrv.sys'
- [HKLM\System\CurrentControlSet\Services\Winmon] 'ImagePath' = '<DRIVERS>\Winmon.sys'
- [HKLM\System\CurrentControlSet\Services\WinmonFS] 'ImagePath' = '<DRIVERS>\WinmonFS.sys'
- [HKLM\System\CurrentControlSet\Services\WinmonProcessMonitor] 'Start' = '00000001'
- [HKLM\System\CurrentControlSet\Services\WinmonProcessMonitor] 'ImagePath' = '<DRIVERS>\WinmonProcessMonitor.sys'
- [HKLM\System\CurrentControlSet\Services\WinDefender] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\WinDefender] 'ImagePath' = '%WINDIR%\windefender.exe'
- 'VBoxWddm' VBoxWddm
- 'VBoxSF' VBoxSF
- 'VBoxMouse' VBoxMouse
- 'VBoxGuest' VBoxGuest
- 'VBoxService' VBoxService
- 'VBoxVideo' VBoxVideo
- 'VBoxDrv' <DRIVERS>\VBoxDrv.sys
- 'Winmon' <DRIVERS>\Winmon.sys
- 'WinmonFS' <DRIVERS>\WinmonFS.sys
- 'WinmonProcessMonitor' <DRIVERS>\WinmonProcessMonitor.sys
- 'WinDefender' %WINDIR%\windefender.exe
- Обновления системы (Windows Update)
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\rss' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\csrss' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\windefender.exe' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<DRIVERS>' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'csrss.exe' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'windefender.exe' = '00000000'
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] '<Имя файла>.exe' = '00000000'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes
- [HKLM\System\CurrentControlSet\Services\WinmonFS] 'Group' = 'FSFilter Activity Monitor'
- %WINDIR%\rss\csrss.exe
- <DRIVERS>\winmonprocessmonitor.sys
- <DRIVERS>\winmonfs.sys
- <DRIVERS>\winmon.sys
- <DRIVERS>\vboxdrv.sys
- %TEMP%\csrss\dsefix.exe
- %TEMP%\symbols\winload_prod.pdb\768283ca443847fb8822f9db1f36ecc51\download.error
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error
- %TEMP%\osloader.exe
- %TEMP%\ntkrnlmp.exe
- %TEMP%\symsrv.dll
- %TEMP%\dbghelp.dll
- %TEMP%\csrss\injector\ntquerysysteminformationhook.dll
- %TEMP%\csrss\injector\injector.exe
- %TEMP%\csrss\patch.exe
- nul
- winmon
- %WINDIR%\windefender.exe
- %WINDIR%\windefender.exe
- %TEMP%\csrss\patch.exe
- %TEMP%\csrss\dsefix.exe
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error в %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\ntkrnlmp.pdb
- %TEMP%\symbols\winload_prod.pdb\768283ca443847fb8822f9db1f36ecc51\download.error в %TEMP%\symbols\winload_prod.pdb\768283ca443847fb8822f9db1f36ecc51\winload_prod.pdb
- %TEMP%\ntkrnlmp.exe в <SYSTEM32>\ntkrnlmp.exe
- %TEMP%\osloader.exe в <SYSTEM32>\osloader.exe
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error
- %TEMP%\symbols\winload_prod.pdb\768283ca443847fb8822f9db1f36ecc51\download.error
- 'msdl.microsoft.com':443
- 'vs###########ssu5shard10.blob.core.windows.net':443
- 'vs###########ssu5shard58.blob.core.windows.net':443
- 'se#####.cdneurops.health':443
- 'cd#.##scordapp.com':443
- 'tw###xis.com':443
- 'msdl.microsoft.com':443
- 'vs###########ssu5shard10.blob.core.windows.net':443
- '34.##0.144.191':443
- 'vs###########ssu5shard58.blob.core.windows.net':443
- 'cd#.##scordapp.com':443
- 'se#####.cdneurops.health':443
- 'tw###xis.com':443
- DNS ASK ce##############97-afba-6f81275fe813.uuid.cdneurops.health
- DNS ASK msdl.microsoft.com
- DNS ASK vs###########ssu5shard10.blob.core.windows.net
- DNS ASK vs###########ssu5shard58.blob.core.windows.net
- DNS ASK stun3.l.google.com
- DNS ASK cd#.##scordapp.com
- DNS ASK se#####.cdneurops.health
- DNS ASK tw###xis.com
- 'stun3.l.google.com':19302
- '%WINDIR%\rss\csrss.exe'
- '%WINDIR%\windefender.exe'
- '%TEMP%\csrss\injector\injector.exe' taskmgr.exe %TEMP%\csrss\injector\NtQuerySystemInformationHook.dll
- '%TEMP%\csrss\patch.exe'
- '%TEMP%\csrss\dsefix.exe'
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} inherit {bootloadersettings}' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -displayorder {71A3C7FC-F751-4982-AEC1-E958357E6813} -addlast' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -timeout 0' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -default {71A3C7FC-F751-4982-AEC1-E958357E6813}' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' /v' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nx OptIn' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"' (со скрытым окном)
- '%TEMP%\csrss\dsefix.exe' ' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nointegritychecks 1' (со скрытым окном)
- '%TEMP%\csrss\patch.exe' ' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} recoveryenabled 0' (со скрытым окном)
- '%WINDIR%\rss\csrss.exe' ' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /delete /tn ScheduledUpdate /f' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} kernel ntkrnlmp.exe' (со скрытым окном)
- '%TEMP%\csrss\injector\injector.exe' taskmgr.exe %TEMP%\csrss\injector\NtQuerySystemInformationHook.dll' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -create {71A3C7FC-F751-4982-AEC1-E958357E6813} -d "Windows Fast Mode" -application OSLOADER' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} device partition=C:' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} osdevice partition=C:' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} systemroot \Windows' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} path \Windows\system32\osloader.exe' (со скрытым окном)
- '%WINDIR%\windefender.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"
- '%WINDIR%\syswow64\sc.exe' sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD...
- '%WINDIR%\syswow64\sc.exe' sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\sc.exe' sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '<SYSTEM32>\bcdedit.exe' /v
- '<SYSTEM32>\bcdedit.exe' -default {71A3C7FC-F751-4982-AEC1-E958357E6813}
- '<SYSTEM32>\bcdedit.exe' -timeout 0
- '<SYSTEM32>\bcdedit.exe' -displayorder {71A3C7FC-F751-4982-AEC1-E958357E6813} -addlast
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} inherit {bootloadersettings}
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nx OptIn
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} recoveryenabled 0
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} kernel ntkrnlmp.exe
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} path \Windows\system32\osloader.exe
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} systemroot \Windows
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} osdevice partition=C
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} device partition=C
- '<SYSTEM32>\bcdedit.exe' -create {71A3C7FC-F751-4982-AEC1-E958357E6813} -d "Windows Fast Mode" -application OSLOADER
- '<SYSTEM32>\schtasks.exe' /delete /tn ScheduledUpdate /f
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nointegritychecks 1
- '%WINDIR%\syswow64\sc.exe' sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)