Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Мiсrosоft Оffiсе' = 'C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\update.exe'
- %TEMP%\RarSFX0\11.exe
- %TEMP%\RarSFX1\hi.exe
- %TEMP%\RarSFX1\1.txt
- %TEMP%\aut1.tmp
- C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\updateupdate.exe
- C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\update.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\version[1].inf
- %TEMP%\aut1.tmp
- %TEMP%\RarSFX1\hi.exe
- %TEMP%\RarSFX0\11.exe
- %TEMP%\RarSFX1\1.txt в C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\1.txt
- '91.##7.16.122':21
- 'h1#####.s22.test-hf.su':80
- http://h1#####.s22.test-hf.su/program/hight/version.inf
- DNS ASK www.google.com
- DNS ASK h1#####.s22.test-hf.su
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\RarSFX0\11.exe' -pHUgby9oybn98Buio989yhj
- '%TEMP%\RarSFX1\hi.exe'
- 'C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\updateupdate.exe' -pшгцукФЫВАDSfДЭ[ФЫчсЪЪ]sdfsdweФЫвываAsd
- 'C:\ProgrаmDatа\Miсrosоft\Windows\DеviceMetadаtaStоre\еn-US\update.exe'