Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Software updater' = '"%APPDATA%\FreeSoftwareUpdater\updater.exe" -h http://neoupdater.com/'
- '%TEMP%\swupdate-setup-KB0874669A.exe'
- '%TEMP%\nsd4.tmp\ns5.tmp' "%TEMP%\swupdate-setup-KB0874669A.exe"
- '%APPDATA%\FreeSoftwareUpdater\updater.exe' -h http://ne###dater.com/
- '%TEMP%\swupdate-setup-KB0874669A.exe' (загружен из сети Интернет)
- %TEMP%\swupdate-setup-KB0874669A.exe
- %TEMP%\nsd4.tmp\nsExec.dll
- %TEMP%\nsd4.tmp\ns5.tmp
- %TEMP%\nsd4.tmp\NSISdl.dll
- %APPDATA%\FreeSoftwareUpdater\updater.exe
- %TEMP%\nsy3.tmp
- %TEMP%\nsd4.tmp\System.dll
- %TEMP%\nsd4.tmp\NSISdl.dll
- %TEMP%\nsd4.tmp\System.dll
- %TEMP%\nsd4.tmp\ns5.tmp
- %TEMP%\nsd4.tmp\nsExec.dll
- 'cd#.##oupdates.com':80
- cd#.##oupdates.com/update1.exe
- DNS ASK cd#.##oupdates.com
- ClassName: 'Indicator' WindowName: ''