Техническая информация
- [HKLM\System\CurrentControlSet\Services\Registryhost] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Registryhost] 'ImagePath' = '%ALLUSERSPROFILE%\Registryhost.exe'
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\TEMP\rupudvcjdtmf.sys'
- 'Registryhost' %ALLUSERSPROFILE%\Registryhost.exe
- 'WinRing0_1_2_0' %WINDIR%\TEMP\rupudvcjdtmf.sys
- <SYSTEM32>\conhost.exe
- %TEMP%\rarsfx0\kmspicosetup.exe
- %TEMP%\rarsfx0\registryhost.exe
- %ALLUSERSPROFILE%\registryhost.exe
- %WINDIR%\temp\rupudvcjdtmf.sys
- %TEMP%\is-ibp2u.tmp\kmspicosetup.tmp
- %TEMP%\setup log 2025-07-03 #001.txt
- %TEMP%\is-ije3m.tmp\_isetup\_setup64.tmp
- %TEMP%\is-ije3m.tmp\_isetup\_shfoldr.dll
- DNS ASK po##.#ashvault.pro
- ClassName: 'Edit' WindowName: ''
- '%TEMP%\rarsfx0\registryhost.exe'
- '%ALLUSERSPROFILE%\registryhost.exe'
- '%TEMP%\rarsfx0\kmspicosetup.exe'
- '%TEMP%\is-ibp2u.tmp\kmspicosetup.tmp' /SL5="$2025E,2952592,69120,%TEMP%\RarSFX0\KMSpicosetup.exe"
- '<SYSTEM32>\sc.exe' delete "Registryhost"
- '<SYSTEM32>\sc.exe' create "Registryhost" binpath= "%ALLUSERSPROFILE%\Registryhost.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "Registryhost"