Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\rnr20] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rnr20] 'ImagePath' = '"%WINDIR%\SysWOW64\api-ms-win-crt-heap-l1-1-0\rnr20.exe"'
- 'rnr20' "%WINDIR%\SysWOW64\api-ms-win-crt-heap-l1-1-0\rnr20.exe"
- 'rnr20' %WINDIR%\SysWOW64\api-ms-win-crt-heap-l1-1-0\rnr20.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABvAEQAYwAwAG4AaQA9ACAAWwBUAHkAcABFAF0AKAAiAHsAMQB9AHsANAB9AHsAMgB9AHsAMwB9AHsAMAB9ACIALQBmACcAdABvAHIAeQAnACwAJwBTACcALAAnAE8ALgBEAGkAcgAnACwAJwBFAGMAJwAsACcAWQBTAFQARQ...
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe в %WINDIR%\syswow64\api-ms-win-crt-heap-l1-1-0\rnr20.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- '19#.#45.25.228':80
- http://qu####owtowing.com/indexing/N2/
- http://te###lora.com/grup-bo/NWd/
- http://19#.#45.25.228/CKsj8dlGC/olHqNm1L4v7RotsBq6s/8IooPE1MlK8/jLik2S4OYMDB/EjOw/ck9ca7/
- DNS ASK sa#####rcesupports.com
- DNS ASK sa####pharma.com
- DNS ASK la####line88.com
- DNS ASK qu####owtowing.com
- DNS ASK te###lora.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABvAEQAYwAwAG4AaQA9ACAAWwBUAHkAcABFAF0AKAAiAHsAMQB9AHsANAB9AHsAMgB9AHsAMwB9AHsAMAB9ACIALQBmACcAdABvAHIAeQAnACwAJwBTACcALAAnAE8ALgBEAGkAcgAnACwAJwBFAGMAJwAsACcAWQBTAFQARQ...' (со скрытым окном)