Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systemup' = '"%WINDIR%\systemup.exe" stand'
- '<SYSTEM32>\netstat.exe' -ano
- '%WINDIR%\systemup.exe' stand
- '<SYSTEM32>\taskkill.exe' /F /IM systemup.exe
- %WINDIR%\systemup.exe
- 'to###ar.li.ru':80
- 'do###oad.qip.ru':80
- '93.##8.134.11':80
- 'su####arsinfo.net':80
- '25#.#55.255.255':8080
- http://do###oad.qip.ru/pda/qippda2140.cab
- http://su####arsinfo.net/udp/knock.php?ve#################################
- http://to###ar.li.ru/toolbar_setup.exe
- http://su####arsinfo.net/distrib_serv/ip_list.php
- http://do####ad.yandex.ru/bar/firefox/YandexBar.xpi via 93.##8.134.11
- DNS ASK to###ar.li.ru
- DNS ASK do###oad.qip.ru
- DNS ASK do####ad.yandex.ru
- DNS ASK yandex.ru
- DNS ASK su####arsinfo.net
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''