Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'cp.exe' = '%TEMP%\1000214001\cp.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ma.exe' = '%TEMP%\1000215001\ma.exe'
- <SYSTEM32>\tasks\utsysc.exe
- %TEMP%\4fdb51ccdc\utsysc.exe
- %TEMP%\1000214001\cp.exe
- %TEMP%\1000215001\ma.exe
- %TEMP%\150914307177
- %APPDATA%\80c6bf70bf3f8f\cred64.dll
- '18#.#72.128.5':80
- '18#.#72.128.32':80
- http://18#.#72.128.32/cp.exe
- http://18#.#72.128.32/ma.exe
- http://18#.#72.128.5/v8sjh3hs8/Plugins/cred64.dll
- http://18#.#72.128.5/v8sjh3hs8/index.php
- '%TEMP%\4fdb51ccdc\utsysc.exe'
- '%TEMP%\4fdb51ccdc\utsysc.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN Utsysc.exe /TR "%TEMP%\4fdb51ccdc\Utsysc.exe" /F' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN Utsysc.exe /TR "%TEMP%\4fdb51ccdc\Utsysc.exe" /F