Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lmhsvcwow.exe' = '%WINDIR%\lmhsvcwow.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\lmhsvcwow.exe' = '%WINDIR%\lmhsvcwow.exe:*:Enabled:Windows Update Service'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%WINDIR%\lmhsvcwow.exe' = '%WINDIR%\lmhsvcwow.exe:*:Enabled:Windows Update Service'
- '%WINDIR%\lmhsvcwow.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram program="%WINDIR%\lmhsvcwow.exe" name="Windows Update Service" mode=ENABLE scope=ALL profile=ALL
- <SYSTEM32>\B7420BB110B7C15335887CFEE63775BF\unrar.exe
- %WINDIR%\lmhsvcwow.exe
- <SYSTEM32>\B7420BB110B7C15335887CFEE63775BF\unrar.exe
- %WINDIR%\lmhsvcwow.exe
- '89.##7.53.210':8080
- '91.##7.153.48':8080
- '10#.#35.49.220':8080
- '77.##.240.82':8080
- 89.##7.53.210/update/r6DFR_W6F7Q_W6FMQ_W5KVbITEQbbWWQbIcWYRRYOOIcfeeURIIYbf_WGSCOQOQ_iQ_iQ_W51CTQUQ_W
- 91.##7.153.48/update/r6DFR_W6F7Q_W6FMQ_W5KVbITEQbbWWQbIcWYRRYOOIcfeeURIIYbf_WGSCOQOQ_iQ_iQ_W51CTQUQ_W
- 10#.#35.49.220/update/r6DFR_W6F7Q_W6FMQ_W5KVbITEQbbWWQbIcWYRRYOOIcfeeURIIYbf_WGSCOQOQ_iQ_iQ_W51CTQUQ_W
- 77.##.240.82/update/r6DFR_W6F7Q_W6FMQ_W5KVbITEQbbWWQbIcWYRRYOOIcfeeURIIYbf_WGSCOQOQ_iQ_iQ_W51CTQUQ_W