Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\printsmaker] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\printsmaker] 'ImagePath' = '"%WINDIR%\SysWOW64\printsmaker.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABCAHIAdwBuAGIAbABuAHUAcwBuAHkAbwB6AD0AJwBPAGMAdwByAG8AcQBrAHYAbgBhAGQAcgB0ACcAOwAkAEIAbABjAGMAcAB2AGYAZQAgAD0AIAAnADEAMAA4ACcAOwAkAE0AZgBmAHEAcgB5AGoAbAByAGYAYQA9ACcAQwBuAG0AegB...
- %HOMEPATH%\108.exe
- %HOMEPATH%\108.exe в %WINDIR%\syswow64\printsmaker.exe
- http://bi###eemgmt.com/wordpress/5gvh2bvxjk-adyl4d-51055/
- http://www.bi###eemgmt.com/wordpress/5gvh2bvxjk-adyl4d-51055/
- http://ad#####tycreative.com/x92k25/StPHhUr/
- http://59.###.126.129:443/v4fNcclvnLuJ via 59.##5.126.129
- DNS ASK bi###eemgmt.com
- DNS ASK ad#####tycreative.com
- '%HOMEPATH%\108.exe'
- '%WINDIR%\syswow64\printsmaker.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABCAHIAdwBuAGIAbABuAHUAcwBuAHkAbwB6AD0AJwBPAGMAdwByAG8AcQBrAHYAbgBhAGQAcgB0ACcAOwAkAEIAbABjAGMAcAB2AGYAZQAgAD0AIAAnADEAMAA4ACcAOwAkAE0AZgBmAHEAcgB5AGoAbAByAGYAYQA9ACcAQwBuAG0AegB...' (со скрытым окном)