Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\xdwdSysHostHelper.exe,'
- [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %WINDIR%\xdwdSysHostHelper.exe'
- <SYSTEM32>\tasks\winsecuritymonitor
- <SYSTEM32>\tasks\winsecuritymonitor_repeat
- <Имя диска съемного носителя>:\nettelemetrybroker.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%WINDIR%' -ErrorAction SilentlyContinue"
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="WindowsControl" dir=in action=allow program="%WINDIR%\xdwdSysHostHelper.exe" enable=yes
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="WindowsControl" dir=out action=allow program="%WINDIR%\xdwdSysHostHelper.exe" enable=yes
- Процесс iexplore.exe, модуль iphlpapi.dll
- Процесс firefox.exe, модуль iphlpapi.dll
- Процесс xdwdsyshosthelper.exe, модуль IPHLPAPI.DLL
- Процесс xdwdsyshosthelper.exe, модуль ntdll.dll
- Процесс powershell.exe, модуль ntdll.dll
- %WINDIR%\xdwdsyshosthelper.exe
- %WINDIR%\xdwd.dll
- %ProgramFiles%\xdwdtaskhostw.exe
- %WINDIR%\xdwd.dll
- %WINDIR%\xdwdsyshosthelper.exe
- %ProgramFiles%\xdwdtaskhostw.exe
- %WINDIR%\xdwd.dll
- %WINDIR%\xdwd.dll в %WINDIR%\xdwd.dll.8998d1f5.old
- 'ap#.#pify.org':443
- 'ic###azip.com':443
- 'ip##fo.io':443
- 'x1.#.lencr.org':80
- 'wi#####ks.duckdns.org':9469
- 'vv#####91.duckdns.org':9469
- http://x1.#.lencr.org/
- 'ap#.#pify.org':443
- 'ic###azip.com':443
- 'ip##fo.io':443
- 'cr#####nana.duckdns.org':9469
- DNS ASK ap#.#pify.org
- DNS ASK ic###azip.com
- DNS ASK ip##fo.io
- DNS ASK x1.#.lencr.org
- DNS ASK wi#####ks.duckdns.org
- DNS ASK vv#####91.duckdns.org
- '%WINDIR%\xdwdsyshosthelper.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "WinSecurityMonitor" /tr "\"%WINDIR%\xdwdSysHostHelper.exe\"" /sc onlogon /rl highest /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WinSecurityMonitor_repeat" /tr "\"%WINDIR%\xdwdSysHostHelper.exe\"" /sc minute /mo 1 /rl highest /f
- '<SYSTEM32>\schtasks.exe' /run /tn "WinSecurityMonitor"
- '<SYSTEM32>\wbem\wmiapsrv.exe'
- '<SYSTEM32>\sc.exe' create "WinSecurityUpdate" binPath= "\"%WINDIR%\xdwdSysHostHelper.exe\"" start= auto
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsUpdateTask" /tr "\"%ProgramFiles%\xdwdtaskhostw.exe\"" /sc onlogon /rl highest /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsUpdateTask_repeat" /tr "\"%ProgramFiles%\xdwdtaskhostw.exe\"" /sc minute /mo 30 /rl highest /f