Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winupdates32' = '<SYSTEM32>\System32\winsupdates32.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winupdates32' = '<SYSTEM32>\System32\winsupdates32.exe'
- [<HKLM>\Software\Microsoft\Active Setup\Installed Components\{347LV342-2RU5-3E8W-E6VB-D062SPL1L6X7}] 'StubPath' = '<SYSTEM32>\System32\winsupdates32.exe Restart'
- <SYSTEM32>\system32\winsupdates32.exe
- <SYSTEM32>\system32\database.dat
- <SYSTEM32>\system32\database.dat
- '<LOCALNET>.11.53':8000
- DNS ASK mi######tservers.no-ip.info
- '%ProgramFiles%\internet explorer\iexplore.exe'