Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemUpdater' = '%APPDATA%\Microsoft\SystemData\WinUpdateService.exe'
- '<SYSTEM32>\taskkill.exe' /F /IM chrome.exe
- '<SYSTEM32>\taskkill.exe' /F /IM msedge.exe
- %TEMP%\_mei30802\pil\_avif.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imaging.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingcms.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingmath.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingtk.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_webp.cp314-win_amd64.pyd
- %TEMP%\_mei30802\vcruntime140.dll
- %TEMP%\_mei30802\vcruntime140_1.dll
- %TEMP%\_mei30802\_asyncio.pyd
- %TEMP%\_mei30802\_bz2.pyd
- %TEMP%\_mei30802\_ctypes.pyd
- %TEMP%\_mei30802\_decimal.pyd
- %TEMP%\_mei30802\_elementtree.pyd
- %TEMP%\_mei30802\_hashlib.pyd
- %TEMP%\_mei30802\_lzma.pyd
- %TEMP%\_mei30802\_multiprocessing.pyd
- %TEMP%\_mei30802\_overlapped.pyd
- %TEMP%\_mei30802\_queue.pyd
- %TEMP%\_mei30802\_socket.pyd
- %TEMP%\_mei30802\_sqlite3.pyd
- %TEMP%\_mei30802\_ssl.pyd
- %TEMP%\_mei30802\_wmi.pyd
- %TEMP%\_mei30802\_zstd.pyd
- %TEMP%\_mei30802\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei30802\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei30802\base_library.zip
- %TEMP%\_mei30802\certifi\cacert.pem
- %TEMP%\_mei30802\charset_normalizer\md.cp314-win_amd64.pyd
- %TEMP%\_mei30802\charset_normalizer\md__mypyc.cp314-win_amd64.pyd
- %TEMP%\_mei30802\libcrypto-3.dll
- %TEMP%\_mei30802\libffi-8.dll
- %TEMP%\_mei30802\libssl-3.dll
- %TEMP%\_mei30802\pyexpat.pyd
- %TEMP%\_mei30802\python314.dll
- %TEMP%\_mei30802\pywin32_system32\pywintypes314.dll
- %TEMP%\_mei30802\select.pyd
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei30802\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei30802\sqlite3.dll
- %TEMP%\_mei30802\ucrtbase.dll
- %TEMP%\_mei30802\unicodedata.pyd
- %TEMP%\_mei30802\win32\win32crypt.pyd
- %APPDATA%\microsoft\systemdata\winupdateservice.exe
- %TEMP%\_mei30802\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei30802\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei30802\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei30802\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei30802\base_library.zip
- %TEMP%\_mei30802\certifi\cacert.pem
- %TEMP%\_mei30802\charset_normalizer\md.cp314-win_amd64.pyd
- %TEMP%\_mei30802\charset_normalizer\md__mypyc.cp314-win_amd64.pyd
- %TEMP%\_mei30802\libcrypto-3.dll
- %TEMP%\_mei30802\libffi-8.dll
- %TEMP%\_mei30802\libssl-3.dll
- %TEMP%\_mei30802\pil\_avif.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imaging.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingcms.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingmath.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_imagingtk.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pil\_webp.cp314-win_amd64.pyd
- %TEMP%\_mei30802\pyexpat.pyd
- %TEMP%\_mei30802\python314.dll
- %TEMP%\_mei30802\pywin32_system32\pywintypes314.dll
- %TEMP%\_mei30802\select.pyd
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei30802\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei30802\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei30802\sqlite3.dll
- %TEMP%\_mei30802\ucrtbase.dll
- %TEMP%\_mei30802\unicodedata.pyd
- %TEMP%\_mei30802\vcruntime140.dll
- %TEMP%\_mei30802\vcruntime140_1.dll
- %TEMP%\_mei30802\win32\win32crypt.pyd
- %TEMP%\_mei30802\_asyncio.pyd
- %TEMP%\_mei30802\_bz2.pyd
- %TEMP%\_mei30802\_ctypes.pyd
- %TEMP%\_mei30802\_decimal.pyd
- %TEMP%\_mei30802\_elementtree.pyd
- %TEMP%\_mei30802\_hashlib.pyd
- %TEMP%\_mei30802\_lzma.pyd
- %TEMP%\_mei30802\_multiprocessing.pyd
- %TEMP%\_mei30802\_overlapped.pyd
- %TEMP%\_mei30802\_queue.pyd
- %TEMP%\_mei30802\_socket.pyd
- %TEMP%\_mei30802\_sqlite3.pyd
- %TEMP%\_mei30802\_ssl.pyd
- %TEMP%\_mei30802\_wmi.pyd
- %TEMP%\_mei30802\_zstd.pyd
- DNS ASK di##ord.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM chrome.exe" (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM msedge.exe" (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "netsh wlan show profiles" (со скрытым окном)
- '<SYSTEM32>\netsh.exe' wlan show profiles
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdater /t REG_SZ /d %APPDATA%\Microsoft\SystemData\WinUpdateService.exe /f