Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinUpdate' = '<SYSTEM32>\winupd.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{90DBB402-D533-02CC-9248-34808BC7272A}] 'StubPath' = '<SYSTEM32>\winupd.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\winupd.exe
- %TEMP%\vkd32.exe
- %TEMP%\sysdx.exe
- 'gi##.no-ip.info':555
- DNS ASK gi##.no-ip.info
- ClassName: 'Shell_TrayWnd' WindowName: ''