Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\CQAZMEWF] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\CQAZMEWF] 'ImagePath' = '%ALLUSERSPROFILE%\yqqntjbdratu\uwmwgiaclvem.exe'
- 'CQAZMEWF' %ALLUSERSPROFILE%\yqqntjbdratu\uwmwgiaclvem.exe
- Журнал событий Windows (Windows Event Logging)
- <SYSTEM32>\conhost.exe
- %ALLUSERSPROFILE%\yqqntjbdratu\uwmwgiaclvem.exe
- %WINDIR%\temp\nwpqlclqkuqm.sys
- 'po##.#upportxmr.com':3333
- 'de####tonight.cc':443
- 'po##.#upportxmr.com':3333
- 'de####tonight.cc':443
- DNS ASK po##.#upportxmr.com
- DNS ASK de####tonight.cc
- '%ALLUSERSPROFILE%\yqqntjbdratu\uwmwgiaclvem.exe'
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "CQAZMEWF"
- '<SYSTEM32>\sc.exe' create "CQAZMEWF" binpath= "%ALLUSERSPROFILE%\yqqntjbdratu\uwmwgiaclvem.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "CQAZMEWF"
- '<SYSTEM32>\conhost.exe'