Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Check Update' = '%TEMP%\{e3b0e851-972f-226b-ebcc-1a78bf217baa}\nTuf96q9.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\msiexec.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\msiexec.exe
- %TEMP%\423500224
- %TEMP%\nsg2.tmp
- 'da###bil.info':80
- http://ds.download.windowsupdate.com/
- DNS ASK da###bil.info
- DNS ASK ds.download.windowsupdate.com