Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OneDriveUpdate' = '<Full path to file>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OneDriveBackgroundTask' = '<Full path to file>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SecurityHealthService' = '<Full path to file>'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<SYSTEM32>\WinRing0x64.sys'
- 'WinRing0_1_2_0' <SYSTEM32>\WinRing0x64.sys
- <SYSTEM32>\rundll32.exe
- jtzqs.exe process, ntdll.dll module
- 'xm#.##yptex.network':7029
- 'xm#.##yptex.network':7029
- DNS ASK xm#.##yptex.network
- '<SYSTEM32>\rundll32.exe'
- '<SYSTEM32>\rundll32.exe' ' (with hidden window)