Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'WinUpdates' = '%WINDIR%\windupdate\svchost.exe'
- '%WINDIR%\windupdate\svchost.exe'
- %WINDIR%\windupdate\vistas.dll
- %WINDIR%\windupdate\svchost.exe
- %WINDIR%\windupdate\vistas.dll
- 'dd###4x7.cz.cc':80
- dd###4x7.cz.cc/config/getcmd.php?id####################
- DNS ASK ni###d.cz.cc
- DNS ASK dd###4x7.cz.cc
- DNS ASK da###64.cz.cc