Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Google Update' = '<LS_APPDATA>\Google\Update\gupdate.exe /app 5FB937CF206A8D11325A58BE2BFC83C8'
- %HOMEPATH%\Start Menu\Programs\Startup\winupdate.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\NvUpdService] 'Start' = '00000002'
- <LS_APPDATA>\NVIDIA Corporation\Update\daemonupd.exe /svc 5FB937CF206A8D11325A58BE2BFC83C8
- <LS_APPDATA>\Google\Update\gupdate.exe
- <LS_APPDATA>\Microsoft\Windows\winupdate.exe
- <LS_APPDATA>\NVIDIA Corporation\Update\daemonupd.exe
- %TEMP%\nso2.tmp
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\nst3.tmp\System.dll
- 'se######.192-168-0-255.com':8000
- 'se######3.reportgoogle.com':8000
- 'se######.reportgoogle.com':8000
- 'se######9.192-168-0-255.com':8000
- 'se######.reportalexa.com':8000
- 'se######3.reportalexa.com':8000
- 'se######6.192-168-0-255.com':8000
- 'se######5.192-168-0-255.com':8000
- DNS ASK se######.192-168-0-255.com
- DNS ASK se######3.reportgoogle.com
- DNS ASK se######.reportgoogle.com
- DNS ASK se######9.192-168-0-255.com
- DNS ASK se######.reportalexa.com
- DNS ASK se######3.reportalexa.com
- DNS ASK se######6.192-168-0-255.com
- DNS ASK se######5.192-168-0-255.com
- ClassName: 'Indicator' WindowName: ''