Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'updata' = 'C:\updata.exe'
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v updata /t REG_SZ /d C:\updata.exe /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v updata /t REG_SZ /d C:\updata.exe /f
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- из <Полный путь к файлу> в C:\updata.exe
- 'ch####u.f3322.net':8002
- DNS ASK ch####u.f3322.net
- ClassName: '18467-41' WindowName: ''