Техническая информация
- <SYSTEM32>\tasks\updates\dzqhttcrei
- '<SYSTEM32>\cmd.exe' /C PO^W^ERs^HE^ll -E WwBTAHkAUwBUAEUAbQAuAHQARQBYAFQALgBlAG4AQwBPAGQAaQBuAGcAXQA6ADoAdQBuAEkAYwBPAEQARQAuAGcAZQBUAHMAVABSAGkATgBnACgAWwBTAHkAcwB0AEUATQAuAEMATwBOAHYAZQByAFQAXQA6ADoARgBSAG8ATQBi...
- snqt7rmrzsqv.exe
- %HOMEPATH%\bitfad2.tmp
- %APPDATA%\dzqhttcrei.exe
- %TEMP%\tmp3f5c.tmp
- %TEMP%\7d1d6c755c\log.txt
- %HOMEPATH%\bitfad2.tmp
- %TEMP%\tmp3f5c.tmp
- %HOMEPATH%\bitfad2.tmp в %HOMEPATH%\snqt7rmrzsqv.exe
- http://go###izm.com/wp-content/themes/busify/tr/855107306.jpg
- http://ap#.#pify.org/
- DNS ASK go###izm.com
- DNS ASK ap#.#pify.org
- '%HOMEPATH%\snqt7rmrzsqv.exe'
- '<SYSTEM32>\cmd.exe' /C PO^W^ERs^HE^ll -E WwBTAHkAUwBUAEUAbQAuAHQARQBYAFQALgBlAG4AQwBPAGQAaQBuAGcAXQA6ADoAdQBuAEkAYwBPAEQARQAuAGcAZQBUAHMAVABSAGkATgBnACgAWwBTAHkAcwB0AEUATQAuAEMATwBOAHYAZQByAFQAXQA6ADoARgBSAG8ATQBi...' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\DzQhtTCrEi" /XML "%TEMP%\tmp3F5C.tmp"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E WwBTAHkAUwBUAEUAbQAuAHQARQBYAFQALgBlAG4AQwBPAGQAaQBuAGcAXQA6ADoAdQBuAEkAYwBPAEQARQAuAGcAZQBUAHMAVABSAGkATgBnACgAWwBTAHkAcwB0AEUATQAuAEMATwBOAHYAZQByAFQAXQA6ADoARgBSAG8ATQBiAGEAUwBlADYANABTAF...
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\DzQhtTCrEi" /XML "%TEMP%\tmp3F5C.tmp"