Техническая информация
- 'C:\users\public\regasm_svchost.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "C:\Users\Public\Regasm_svchost.exe"
- C:\users\public\regasm_svchost.exe
- '19#.#27.158.100':80
- http://19#.#27.158.100/thu/thur.exe
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "C:\Users\Public\Regasm_svchost.exe"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding