Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\services\ModuleDesktopDefender\Parameters] 'ServiceDll' = '<SYSTEM32>\ModuleDesktopDefender.dll'
- [HKLM\System\CurrentControlSet\Services\ModuleDesktopDefender] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ModuleDesktopDefender] 'ImagePath' = '<SYSTEM32>\svchost.exe -k ModuleDesktopDefender'
- 'ModuleDesktopDefender' <SYSTEM32>\svchost.exe -k ModuleDesktopDefender
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>"
- <SYSTEM32>\moduledesktopdefender.dll
- %WINDIR%\mwbpmtzixic.bin
- 'gr###fy.link':443
- 'gr###fy.link':443
- DNS ASK gr###fy.link
- '<SYSTEM32>\svchost.exe' -k ModuleDesktopDefender
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>" (со скрытым окном)