Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\JBGJZMPB] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\JBGJZMPB] 'ImagePath' = '%ALLUSERSPROFILE%\dkmzcxjhvrmo\lkkxsckqbhiy.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\TEMP\hofwkracizhz.sys'
- 'JBGJZMPB' %ALLUSERSPROFILE%\dkmzcxjhvrmo\lkkxsckqbhiy.exe
- 'WinRing0_1_2_0' %WINDIR%\TEMP\hofwkracizhz.sys
- Журнал событий Windows (Windows Event Logging)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramData) -ExclusionExtension '.exe' -Force
- <SYSTEM32>\conhost.exe
- %ALLUSERSPROFILE%\dkmzcxjhvrmo\lkkxsckqbhiy.exe
- %WINDIR%\temp\__psscriptpolicytest_ce0vyvmf.li5.ps1
- %WINDIR%\temp\__psscriptpolicytest_q110dlhr.fyg.psm1
- %WINDIR%\temp\__psscriptpolicytest_diezetpj.3j3.ps1
- %WINDIR%\temp\__psscriptpolicytest_mkjaw1gy.i0w.psm1
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
- %WINDIR%\temp\hofwkracizhz.sys
- %WINDIR%\temp\__psscriptpolicytest_ce0vyvmf.li5.ps1
- %WINDIR%\temp\__psscriptpolicytest_q110dlhr.fyg.psm1
- %WINDIR%\temp\__psscriptpolicytest_diezetpj.3j3.ps1
- %WINDIR%\temp\__psscriptpolicytest_mkjaw1gy.i0w.psm1
- '18#.#16.71.180':80
- 'xm####.kryptex.network':7029
- 'xm####.kryptex.network':7029
- DNS ASK xm####.kryptex.network
- '%ALLUSERSPROFILE%\dkmzcxjhvrmo\lkkxsckqbhiy.exe'
- '<SYSTEM32>\cmd.exe' /c wusa /uninstall /kb:890830 /quiet /norestart
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "JBGJZMPB"
- '<SYSTEM32>\sc.exe' create "JBGJZMPB" binpath= "%ALLUSERSPROFILE%\dkmzcxjhvrmo\lkkxsckqbhiy.exe" start= "auto"
- '<SYSTEM32>\wusa.exe' /uninstall /kb:890830 /quiet /norestart
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "JBGJZMPB"
- '<SYSTEM32>\conhost.exe'