Техническая информация
- [HKLM\System\CurrentControlSet\Services\MicrosoftWSUS] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\MicrosoftWSUS] 'ImagePath' = '%WINDIR%\Microsoft\Protect\WSUS\Bin\WSUS.exe'
- 'MicrosoftWSUS' %WINDIR%\Microsoft\Protect\WSUS\Bin\WSUS.exe
- Библиотека-обработчик для всех процессов: %WINDIR%\winmy\MYPRO32.dll
- Библиотека-обработчик для всех процессов: %WINDIR%\winmy\MYPRO64.dll
- %TEMP%\is-1i78q.tmp\<Имя файла>.tmp
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-profile-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-rtlsupport-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-string-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-synch-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-synch-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-processthreads-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-processthreads-l1-1-1.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-sysinfo-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-convert-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-environment-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-filesystem-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-heap-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-locale-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-timezone-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-util-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-multibyte-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-math-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-memory-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-console-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-datetime-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-debug-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-errorhandling-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-namedpipe-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\vcruntime140.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-processenvironment-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-file-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-heap-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-interlocked-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-libraryloader-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-localization-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-file-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-file-l2-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-core-handle-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-util-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-runtime-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\wsus.ini
- %WINDIR%\syswow64\wsys.ini
- %WINDIR%\winmy\myfile32.dll
- %WINDIR%\winmy\myfile64.dll
- %WINDIR%\winmy\myijt32.dll
- %WINDIR%\microsoft\protect\wsus\winmy\myqs32.dll
- %WINDIR%\winmy\myijt64.dll
- %WINDIR%\microsoft\protect\wsus\log\wsuslog\20240226 153455.340000.txt
- %WINDIR%\winmy\mypro64.dll
- %WINDIR%\microsoft\protect\wsus\wsus_paexecconf.ini
- %WINDIR%\microsoft\protect\wsus\log\hookmng32\20240226 153459.389000.txt
- %WINDIR%\microsoft\protect\wsus\log\hookmng64\20240226 153500.121000.txt
- %WINDIR%\microsoft\protect\wsus\log\reallog\20240226 153500.792000.txt
- %WINDIR%\winmy\mypro32.dll
- %WINDIR%\microsoft\protect\wsus\winmy\mypro64.dll
- %WINDIR%\winmy\myqs32.dll
- %WINDIR%\microsoft\protect\wsus\winmy\mypro32.dll
- %WINDIR%\microsoft\protect\wsus\winmy\myijt64.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-string-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-utility-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\jsoncpp.dll
- %WINDIR%\microsoft\protect\wsus\bin64\logmanager.dll
- %WINDIR%\microsoft\protect\wsus\bin64\msvcp140.dll
- %WINDIR%\microsoft\protect\wsus\bin64\msvcr120.dll
- %WINDIR%\microsoft\protect\wsus\bin64\ucrtbase.dll
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-time-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin64\vcruntime140.dll
- %WINDIR%\microsoft\protect\wsus\config\cn\crashrptlang.ini
- %WINDIR%\microsoft\protect\wsus\config\crashinfo.ini
- %WINDIR%\microsoft\protect\wsus\winmy\myfile32.dll
- %WINDIR%\microsoft\protect\wsus\winmy\myfile64.dll
- %WINDIR%\microsoft\protect\wsus\winmy\myijt32.dll
- %WINDIR%\microsoft\protect\wsus\bin\ucrtbase.dll
- %WINDIR%\microsoft\protect\wsus\bin64\winmy.exe
- %WINDIR%\microsoft\protect\wsus\bin\wsus.exe
- %WINDIR%\microsoft\protect\wsus\bin\syscommunication.dll
- %WINDIR%\microsoft\protect\wsus\bin\stray.exe
- %WINDIR%\microsoft\protect\wsus\bin\screenclient.exe
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-libraryloader-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-localization-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-memory-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-namedpipe-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-handle-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-file-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-interlocked-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-processenvironment-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-rtlsupport-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-string-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-synch-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-synch-l1-2-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-processthreads-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-processthreads-l1-1-1.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-profile-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-file-l2-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-file-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\is-14l0r.tmp\_isetup\_setup64.tmp
- %TEMP%\is-14l0r.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-14l0r.tmp\kvrt.exe
- %TEMP%\is-14l0r.tmp\gfdfdgffdgnl_lffg.msi
- %WINDIR%\microsoft\protect\installmanager\master.manifest
- %WINDIR%\microsoft\protect\installmanager\winsrvdl.exe
- %TEMP%\is-14l0r.tmp\_isetup\_regdll.tmp
- %WINDIR%\microsoft\protect\installmanager\wsus.zip
- %TEMP%\aa88a3f00f\log\installmanager\20240226 153422.878000.txt
- %WINDIR%\winsrvdl.exe
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-console-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-datetime-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-debug-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-errorhandling-l1-1-0.dll
- %WINDIR%\microsoft\protect\installmanager\winsrvdl.ini
- %WINDIR%\temp\~df20166ad0f4ac1dd1.tmp
- %WINDIR%\microsoft\protect\wsus\bin64\api-ms-win-crt-stdio-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-timezone-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-filesystem-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\mfcm80.dll
- %WINDIR%\microsoft\protect\wsus\bin\mfcm80u.dll
- %WINDIR%\microsoft\protect\wsus\bin\microsoft.vc80.crt.manifest
- %WINDIR%\microsoft\protect\wsus\bin\microsoft.vc80.mfc.manifest
- %WINDIR%\microsoft\protect\wsus\bin\mfc80.dll
- %WINDIR%\microsoft\protect\wsus\bin\msvcp140.dll
- %WINDIR%\microsoft\protect\wsus\bin\mfc80u.dll
- %WINDIR%\microsoft\protect\wsus\bin\msvcr120.dll
- %WINDIR%\microsoft\protect\wsus\bin\policy.dll
- %WINDIR%\microsoft\protect\wsus\bin\protobufnet.dll
- %WINDIR%\microsoft\protect\wsus\bin\quickanalyze.dll
- %WINDIR%\microsoft\protect\wsus\bin\realinfo.exe
- %WINDIR%\microsoft\protect\wsus\bin\msvcp80.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-core-heap-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\msvcr80.dll
- %WINDIR%\microsoft\protect\wsus\bin\mfc80chs.dll
- %WINDIR%\microsoft\protect\wsus\bin\logmanager.dll
- %WINDIR%\microsoft\protect\wsus\bin\jsoncpp.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-heap-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-locale-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-math-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-multibyte-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-runtime-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-environment-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-stdio-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-time-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-utility-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\crashrpt.dll
- %WINDIR%\microsoft\protect\wsus\bin\crashsender.exe
- %WINDIR%\microsoft\protect\wsus\bin\des.dll
- %WINDIR%\microsoft\protect\wsus\bin\fmtray.exe
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-string-l1-1-0.dll
- %WINDIR%\microsoft\protect\wsus\bin\ftpclient.dll
- %WINDIR%\microsoft\protect\wsus\bin\api-ms-win-crt-convert-l1-1-0.dll
- %WINDIR%\temp\~df106468b4419847fc.tmp
- %TEMP%\is-14l0r.tmp\gfdfdgffdgnl_lffg.msi
- %TEMP%\is-14l0r.tmp\kvrt.exe
- %TEMP%\is-14l0r.tmp\_isetup\_regdll.tmp
- %TEMP%\is-14l0r.tmp\_isetup\_setup64.tmp
- %TEMP%\is-14l0r.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-1i78q.tmp\<Имя файла>.tmp
- %WINDIR%\microsoft\protect\installmanager\winsrvdl.ini
- %WINDIR%\microsoft\protect\installmanager\master.manifest в C:\config.msi\f8b58.rbf
- %WINDIR%\microsoft\protect\installmanager\winsrvdl.exe в C:\config.msi\f8b59.rbf
- %WINDIR%\microsoft\protect\installmanager\wsus.zip в C:\config.msi\f8b5a.rbf
- '<LOCALNET>.100.186':6001
- '%TEMP%\is-1i78q.tmp\<Имя файла>.tmp' /SL5="$A0266,118411457,48640,<Полный путь к файлу>"
- '%TEMP%\is-14l0r.tmp\kvrt.exe'
- '%WINDIR%\microsoft\protect\installmanager\winsrvdl.exe' -a "%TEMP%\is-14L0R.tmp\gfdfdgffdgnl_lffg.msi"
- '%WINDIR%\microsoft\protect\wsus\bin\wsus.exe'
- '%WINDIR%\microsoft\protect\wsus\bin\realinfo.exe'
- '%WINDIR%\microsoft\protect\wsus\bin\stray.exe'
- '%WINDIR%\microsoft\protect\wsus\bin64\winmy.exe'
- '%WINDIR%\syswow64\msiexec.exe' /i "%TEMP%\is-14L0R.tmp\gfdfdgffdgnl_lffg.msi" /q' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c msiexec /x "{B7C0DCDE-DB8E-49DE-9FB1-3CCB517BF7D0}" /quiet' (со скрытым окном)
- '%WINDIR%\microsoft\protect\wsus\bin\realinfo.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\msiexec.exe' /i "%TEMP%\is-14L0R.tmp\gfdfdgffdgnl_lffg.msi" /q
- '%WINDIR%\syswow64\cmd.exe' /c msiexec /x "{B7C0DCDE-DB8E-49DE-9FB1-3CCB517BF7D0}" /quiet
- '%WINDIR%\syswow64\msiexec.exe' /x "{B7C0DCDE-DB8E-49DE-9FB1-3CCB517BF7D0}" /quiet