Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Wdf2B9F] 'ImagePath' = '%TEMP%\.000E2B90.sys'
- 'Wdf2B9F' %TEMP%\.000E2B90.sys
- <SYSTEM32>\securityhealthsystray.exe
- <SYSTEM32>\securityhealthservice.exe
- %TEMP%\.000e2b90.sys
- %WINDIR%\temp\.avk.ps1
- %ALLUSERSPROFILE%\microsoft\windows security health\logs\shs-06112026-133708-7-7f-19041.1.amd64fre.vb_release.191206-1406.etl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h -NonInteractive -ep bypass -File %WINDIR%\Temp\.avk.ps1
- '<SYSTEM32>\securityhealthservice.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h -NonInteractive -ep bypass -File %WINDIR%\Temp\.avk.ps1 (со скрытым окном)