Техническая информация
- [HKLM\System\CurrentControlSet\Services\WLJKMJZD] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\WLJKMJZD] 'ImagePath' = '%ALLUSERSPROFILE%\eqflhmxiccso\hsthoehgwnsq.exe'
- 'WLJKMJZD' %ALLUSERSPROFILE%\eqflhmxiccso\hsthoehgwnsq.exe
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\eqflhmxiccso\hsthoehgwnsq.exe
- %WINDIR%\temp\tqrnjywvwzuq.sys
- DNS ASK gu##.##neroocean.stream
- '%ALLUSERSPROFILE%\eqflhmxiccso\hsthoehgwnsq.exe'
- '<SYSTEM32>\sc.exe' delete "WLJKMJZD"
- '<SYSTEM32>\sc.exe' create "WLJKMJZD" binpath= "%ALLUSERSPROFILE%\eqflhmxiccso\hsthoehgwnsq.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "WLJKMJZD"
- '%WINDIR%\explorer.exe'