Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nvFD2' = '"%WINDIR%\nvFD2.exe"'
- <SYSTEM32>\tasks\nvfd2
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -c "Add-MpPreference -ExclusionPath '%WINDIR%' -ExclusionProcess 'nvFD2.exe'"
- Процесс nvfd2.exe, модуль Amsi.dll
- Процесс nvfd2.exe, модуль ntdll.dll
- %WINDIR%\msteamssetup.exe
- %WINDIR%\nvfd2.exe
- '<DNS_SERVER>':53
- 'de##.#hvarmsd.com':443
- 'x1.#.lencr.org':80
- '45.#02.1.50':12159
- http://x1.#.lencr.org/
- 'de##.#hvarmsd.com':443
- '45.#02.1.50':12159
- DNS ASK de##.#hvarmsd.com
- DNS ASK x1.#.lencr.org
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\nvfd2.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "nvFD2" /tr "\"%WINDIR%\nvFD2.exe\"" & exit (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn "nvFD2" /tr "\"%WINDIR%\nvFD2.exe\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -c "Add-MpPreference -ExclusionPath '%WINDIR%' -ExclusionProcess 'nvFD2.exe'" (со скрытым окном)