Техническая информация
- [HKLM\System\CurrentControlSet\Services\wzvm] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\wzvm] 'ImagePath' = 'system32\drivers\cvuxdxq.sys'
- 'wzvm' <DRIVERS>\cvuxdxq.sys
- %TEMP%\rarsfx0\server.exe
- %TEMP%\rarsfx0\91.exe
- %APPDATA%\microsoft\internet explorer\quick launch\æô¶¯ internet explorer ä¯à à æ÷.lnk
- %HOMEPATH%\favorites\Гøö·µ¼º½.url
- %WINDIR%\syswow64\ueba.dll
- %WINDIR%\syswow64\drivers\cvuxdxq.sys
- %WINDIR%\syswow64\1ceq1t.bat
- nul
- %TEMP%\rarsfx0\server.exe
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\server.exe'
- '%TEMP%\rarsfx0\91.exe'
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\1CEq1t.bat (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 3 127.0.0.1