Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WindowsUpdaterService] 'Start' = '00000002'
- '%PROGRAM_FILES%\K14R\WindowsService.exe'
- '%PROGRAM_FILES%\K14R\WindowsService.exe' (загружен из сети Интернет)
- '<SYSTEM32>\sc.exe' start WindowsUpdaterService
- '<SYSTEM32>\sc.exe' create WindowsUpdaterService binPath= "%PROGRAM_FILES%\K14R\WindowsService.exe" start= auto
- %PROGRAM_FILES%\K14R\file2.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\file3[1].txt
- %PROGRAM_FILES%\K14R\file3.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\file2[1].txt
- %TEMP%\nst2.tmp\inetc2.dll
- %PROGRAM_FILES%\K14R\file1.txt
- %TEMP%\nst2.tmp\inetcEXT.dll
- %TEMP%\nst2.tmp\inetcEXT.dll
- %TEMP%\nst2.tmp\inetc2.dll
- %PROGRAM_FILES%\K14R\file3.txt в %PROGRAM_FILES%\K14R\WindowsService.exe
- %PROGRAM_FILES%\K14R\file2.txt в %PROGRAM_FILES%\K14R\uvname.conf
- %PROGRAM_FILES%\K14R\file1.txt в %PROGRAM_FILES%\K14R\lupdater.exe
- 'www.mo####wnloads.info':80
- www.mo####wnloads.info/joe/file3.txt
- www.mo####wnloads.info/joe/file2.txt
- www.mo####wnloads.info/joe/file1.txt
- DNS ASK www.mo####wnloads.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '#32770' WindowName: '(null)'