Техническая информация
- C:\hdsupdate\AppUpdate.exe "c:\hdsupdate\config.dll" start007
- <SYSTEM32>\cacls.exe ""%HOMEPATH%\Local Settings\Temp"" /T /P everyone:F
- <SYSTEM32>\net1.exe start W32Time
- <SYSTEM32>\cacls.exe ""%TEMP%\f1df8c41c94601cd090db545856cb2bc.dat"" /T /P everyone:N
- <SYSTEM32>\attrib.exe +H +R ""%TEMP%\f1df8c41c94601cd090db545856cb2bc.dat""
- <SYSTEM32>\sc.exe config W32Time start=auto
- <SYSTEM32>\sc.exe stop W32Time
- <SYSTEM32>\cmd.exe /c c:\hdsupdate\AppUpdate.exezec.bat
- <SYSTEM32>\wscript.exe c:\xsmfqn\pmhfy.vbs
- C:\xsmfqn\pmhfy.vbs
- C:\hdsupdate\AppUpdate.exezec.bat
- C:\hdsupdate\config.dll
- C:\hdsupdate\AppUpdate.exe
- C:\xsmfqn\pmhfy.vbs
- 'zz#####4757.3322.org':8800
- DNS ASK zz#####4757.3322.org
- DNS ASK ti##.#indows.com
- 'ti##.#indows.com':123
- '<IP-адрес в локальной сети>':123