Техническая информация
- C:\hdsxup\AppUpdate.exe
- <SYSTEM32>\attrib.exe +H +R "%TEMP%\31a9fed7621f135f6e7b9060e202d9a5.dat"
- <SYSTEM32>\net1.exe start W32Time
- <SYSTEM32>\attrib.exe +H +R "c:\hdsxup"
- <SYSTEM32>\cmd.exe /c c:\hdsxup\AppUpdate.exeqmg.bat
- <SYSTEM32>\sc.exe stop W32Time
- <SYSTEM32>\sc.exe config W32Time start=auto
- <SYSTEM32>\wscript.exe c:\vnh6epm\qbs5avt.vbs
- C:\vnh6epm\qbs5avt.vbs
- C:\hdsxup\AppUpdate.exeqmg.bat
- C:\hdsxup\AppUpdate.exe
- C:\hdsxup\common\Utility.dll
- C:\vnh6epm\qbs5avt.vbs
- 'li####2009.3322.org':7096
- DNS ASK li####2009.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''