Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Syshost' = '"%APPDATA%\syshost.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdateSvc' = '%APPDATA%\runtimeenr.exe'
- <SYSTEM32>\tasks\windows security checks
- <SYSTEM32>\sihost.exe
- <SYSTEM32>\runtimebroker.exe
- %WINDIR%\explorer.exe
- Процесс g6sfle4i.exe, модуль Amsi.dll
- Процесс g6sfle4i.exe, модуль ntdll.dll
- %TEMP%\p7a2kfo1.exe
- %TEMP%\81veafwd.exe
- %TEMP%\m8wxduaf.exe
- %TEMP%\v2jioibh.exe
- %TEMP%\g6sfle4i.exe
- %APPDATA%\syshost.exe
- %APPDATA%\runtimeenr.exe
- %TEMP%\is-1rnqqkexd6.tmp\p7a2kfo1.tmp
- %APPDATA%\microsoft\windows\services\wlrmdr.exe
- %TEMP%\is-m3t8mq8tzk.tmp\_isetup\_isdecmp.dll
- %TEMP%\acltylty.exe
- %TEMP%\ba3ythsa.exe
- %TEMP%\is-t4whtc78zr.tmp\ba3ythsa.tmp
- %TEMP%\is-e16k5xoaa9.tmp\_isetup\_isdecmp.dll
- %APPDATA%\syshost.exe
- %APPDATA%\runtimeenr.exe
- %APPDATA%\microsoft\windows\services\wlrmdr.exe
- 'google.com':80
- 'bing.com':80
- '19#.#78.158.107':80
- http://www.google.com/
- http://www.bing.com/
- DNS ASK google.com
- DNS ASK bing.com
- '%TEMP%\p7a2kfo1.exe'
- '%TEMP%\81veafwd.exe'
- '%TEMP%\m8wxduaf.exe'
- '%TEMP%\v2jioibh.exe'
- '%TEMP%\g6sfle4i.exe'
- '%APPDATA%\syshost.exe'
- '%TEMP%\is-1rnqqkexd6.tmp\p7a2kfo1.tmp' /SL5="$1102BC,3755066,888832,%TEMP%\p7a2kfo1.exe"
- '%TEMP%\acltylty.exe'
- '%TEMP%\ba3ythsa.exe'
- '%TEMP%\is-t4whtc78zr.tmp\ba3ythsa.tmp' /SL5="$1000D2,3755066,888832,%TEMP%\ba3ythsa.exe"
- '%APPDATA%\syshost.exe' (со скрытым окном)