Technical Information
- [<HKLM>\System\CurrentControlSet\Services\mfc40] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mfc40] 'ImagePath' = '"%WINDIR%\SysWOW64\mfc40\mfc40.exe"'
- from <Full path to file> to %WINDIR%\syswow64\mfc40\mfc40.exe
- '78.##.27.172':80
- http://78.##.27.172/ficc2/RXcSMpZiDpmvUe/SBUSWF3/KNf33DTOB4jbqgUWcQs/N8WUmmzBD/SmM2XvJKQRGHKRmk1/