Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systemup' = '"%WINDIR%\systemup.exe" stand'
- %WINDIR%\systemup.exe stand
- <SYSTEM32>\netstat.exe -ano
- <SYSTEM32>\taskkill.exe /F /IM systemup.exe
- %WINDIR%\systemup.exe
- '79.##7.91.66':62999
- '18#.#29.179.245':62999
- '10#.#05.25.235':62999
- '24.##9.119.109':62999
- '46.##7.159.134':62999
- '95.##4.56.124':62999
- '78.##2.62.162':62999
- '17#.#65.100.110':62999
- '77.##2.172.94':62999
- '11.#1.11.11':55611
- '83.#8.3.120':62999
- '11.#1.11.11':45717
- 'yo##ube.com':80
- '72.##0.94.70':62999
- '17#.#59.219.34':62999
- '89.##.135.185':62999
- '82.##9.30.19':62999
- yo##ube.com/
- DNS ASK yo##ube.com
- ClassName: '' WindowName: ''