Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\netupdate] 'Start' = '00000002'
- '<SYSTEM32>\net1.exe' start netupdate
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost" /v netupdate /t REG_MULTI_SZ /d netupdate /F
- '<SYSTEM32>\svchost.exe' -k netupdate
- '<SYSTEM32>\ping.exe' 127.0.0.1
- '<SYSTEM32>\net1.exe' stop netupdate
- '<SYSTEM32>\net.exe' stop netupdate
- '<SYSTEM32>\reg.exe' add HKLM\SYSTEM\CurrentControlSet\services\netupdate\Parameters /v ServiceDll /t REG_EXPAND_SZ /d %SystemRoot%\ntrtm.dll /F
- '<SYSTEM32>\sc.exe' create netupdate type= share start= auto binpath= "%SystemRoot%\system32\svchost.exe -k netupdate" displayname= "Network Update Service"
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\updaterc[1].aspx
- %WINDIR%\ntrtm.dll
- %TEMP%\ntrtm.all
- %TEMP%\ntrtm.all
- 'www.do###ys5.com':80
- 'localhost':1036
- www.do###ys5.com/rc/updaterc.aspx?no#################################################################
- DNS ASK www.do###ys5.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'