Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\GIYEHSWI] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\GIYEHSWI] 'ImagePath' = '%ALLUSERSPROFILE%\lerfehjeiwba\vtrubwidnbpl.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\TEMP\zbjsfxiszbxz.sys'
- 'GIYEHSWI' %ALLUSERSPROFILE%\lerfehjeiwba\vtrubwidnbpl.exe
- 'WinRing0_1_2_0' %WINDIR%\TEMP\zbjsfxiszbxz.sys
- Журнал событий Windows (Windows Event Logging)
- <SYSTEM32>\conhost.exe
- %ALLUSERSPROFILE%\lerfehjeiwba\vtrubwidnbpl.exe
- %WINDIR%\temp\zbjsfxiszbxz.sys
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK po##.#ashvault.pro
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%ALLUSERSPROFILE%\lerfehjeiwba\vtrubwidnbpl.exe'
- '<SYSTEM32>\sc.exe' delete "GIYEHSWI"
- '<SYSTEM32>\sc.exe' create "GIYEHSWI" binpath= "%ALLUSERSPROFILE%\lerfehjeiwba\vtrubwidnbpl.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "GIYEHSWI"