Техническая информация
- [HKLM\System\CurrentControlSet\Services\OYQXLWCB] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\OYQXLWCB] 'ImagePath' = '%ALLUSERSPROFILE%\djtpcthapnrx\eskzkjmqrwyk.exe'
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\TEMP\xwiehzrrhujz.sys'
- 'OYQXLWCB' %ALLUSERSPROFILE%\djtpcthapnrx\eskzkjmqrwyk.exe
- 'WinRing0_1_2_0' %WINDIR%\TEMP\xwiehzrrhujz.sys
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\djtpcthapnrx\eskzkjmqrwyk.exe
- %WINDIR%\temp\xwiehzrrhujz.sys
- 'ze#####1.nanopool.org':10943
- 'pa###bin.com':443
- 'vh#####9.hostline.su':80
- http://vh#####9.hostline.su/api/endpoint.php
- 'ze#####1.nanopool.org':10943
- 'pa###bin.com':443
- DNS ASK ze#####1.nanopool.org
- DNS ASK pa###bin.com
- DNS ASK vh#####9.hostline.su
- '%ALLUSERSPROFILE%\djtpcthapnrx\eskzkjmqrwyk.exe'
- '<SYSTEM32>\sc.exe' delete "OYQXLWCB"
- '<SYSTEM32>\sc.exe' create "OYQXLWCB" binpath= "%ALLUSERSPROFILE%\djtpcthapnrx\eskzkjmqrwyk.exe" start= "auto"
- '<SYSTEM32>\sc.exe' start "OYQXLWCB"
- '<SYSTEM32>\sc.exe' stop eventlog
- '%WINDIR%\explorer.exe'