Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winsat Update' = '<LS_APPDATA>\HPQ\hpqprotect.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{adws-sdws-asgt-bet9}' = '%APPDATA%\UPDTHPP\hppupdate.exe'
- %WINDIR%\Tasks\WPUDTEx.job
- '%APPDATA%\UPDTHPP\hppupdate.exe'
- '<SYSTEM32>\schtasks.exe' /CREATE /SC HOURLY /MO 5 /TN "WPUDTE7" /ST 00:00:00 /SD 10/10/2013 /TR "%APPDATA%\UPDTHPP\hppupdate.exe"
- '<SYSTEM32>\schtasks.exe' /CREATE /SC HOURLY /MO 5 /TN "WPUDTEx" /ST 00:00:00 /SD 10/10/2013 /TR "%APPDATA%\UPDTHPP\hppupdate.exe" /RU SYSTEM
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\UPDTHPP\wn7.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\UPDTHPP\wnxp.bat" "
- %APPDATA%\UPDTHPP\wnxp.bat
- %APPDATA%\UPDTHPP\wn7.bat
- %APPDATA%\UPDTHPP\hppupdate.exe
- '80.##1.223.183':80
- 'wp#d':80
- 80.##1.223.183/~ivan/web.html?14########
- 80.##1.223.183/~ivan/web.html?17########
- 80.##1.223.183/~ivan/web.html?21########
- 80.##1.223.183/~ivan/web.html?11########
- wp#d/wpad.dat
- 80.##1.223.183/~ivan/web.html?45######
- 80.##1.223.183/~ivan/web.html?15#######
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'