Техническая информация
- [HKLM\System\CurrentControlSet\Services\DJHQJBTG] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\DJHQJBTG] 'ImagePath' = '%ALLUSERSPROFILE%\amcnnbrqpkzp\jisxxrhocdvo.exe'
- 'DJHQJBTG' %ALLUSERSPROFILE%\amcnnbrqpkzp\jisxxrhocdvo.exe
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\amcnnbrqpkzp\jisxxrhocdvo.exe
- %WINDIR%\temp\qkwywhpjyijv.sys
- '34.##9.100.209':443
- DNS ASK lo###his.space
- DNS ASK ra#.####ubusercontent.com
- '%ALLUSERSPROFILE%\amcnnbrqpkzp\jisxxrhocdvo.exe'
- '<SYSTEM32>\sc.exe' stop UsoSvc
- '<SYSTEM32>\sc.exe' stop WaaSMedicSvc
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' stop bits
- '<SYSTEM32>\sc.exe' stop dosvc
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "DJHQJBTG"
- '<SYSTEM32>\sc.exe' create "DJHQJBTG" binpath= "%ALLUSERSPROFILE%\amcnnbrqpkzp\jisxxrhocdvo.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "DJHQJBTG"
- '%WINDIR%\explorer.exe'