Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'C:\ProgramData\TEMP\fveupdate.exe' = 'C:\ProgramData\TEMP\fveupdate.ex...
- '<SYSTEM32>\schtasks.exe' /create /RU "SYSTEM" /TN "Comunity update" /TR C:\ProgramData\mnc.exe /SC HOURLY /F
- 'C:\ProgramData\TEMP\fveupdate.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks
- '<SYSTEM32>\schtasks.exe'
- <SYSTEM32>\Macromed\Flash\FlashPlayerUpdateService.exe
- C:\ProgramData\Adobe\AAMUpdater.exe
- C:\ProgramData\TEMP\fveupdate.exe
- 'c0.#pts.com':80
- http://c.##ts.com/urlsvc5/creq276dc.css via c0.#pts.com
- http://c.##ts.com/urlsvc5/creq2763f.htm via c0.#pts.com
- DNS ASK c0.#pts.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''