Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'WindowsUpDate' = 'winu'
- '<SYSTEM32>\wscript.exe' c:\1.vbs
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -Embedding
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hihi.kvalitne[1]
- C:\1.vbs
- <SYSTEM32>\winupd.exe
- 'hi##.#valitne.cz':80
- 'localhost':1036
- http://hi##.#valitne.cz/?u=########
- DNS ASK hi##.#valitne.cz
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''