Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systemup' = '"%WINDIR%\systemup.exe" stand'
- %WINDIR%\systemup.exe stand
- <SYSTEM32>\netstat.exe -ano
- <SYSTEM32>\taskkill.exe /F /IM systemup.exe
- %WINDIR%\systemup.exe
- '17#.#06.12.250':62999
- '89.##9.175.205':62999
- '95.##.246.72':62999
- '93.##3.98.91':62999
- '79.##3.58.98':62999
- '18#.#63.2.72':62999
- '89.##2.50.173':62999
- '86.##5.251.129':62999
- '11.#1.11.11':55611
- '21#.80.2.18':62999
- '11.#1.11.11':45717
- 'yo##ube.com':80
- '46.##4.181.10':62999
- '95.##.225.23':62999
- '10#.#6.215.62':62999
- '93.##4.187.104':62999
- yo##ube.com/
- DNS ASK yo##ube.com
- ClassName: '' WindowName: ''