Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Microsoft Update.exe' = '"%LOCALAPPDATA%\Microsoft Update.exe"'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'Microsoft Update.exe' = '"%LOCALAPPDATA%\Microsoft Update.exe"'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\5972956092.txt
- %TEMP%\59729560.txt
- %LOCALAPPDATA%\microsoft update.exe
- 'ns#.##ltaluse.ml':8085
- http://xm####rvices.com/C/BDEF_BFDBEBFFDEFAFBEDEECGAGFBBADCDCBCBFDGGBFEDEE_GDAFDA.txt
- DNS ASK pa###bin.com
- DNS ASK xm####rvices.com
- DNS ASK ns#.##ltaluse.ml
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 240 /tn Microsoft Update.exe /tr "powershell start %LOCALAPPDATA%\Microsoft Update.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 240 /tn Microsoft Update.exe /tr "powershell start %LOCALAPPDATA%\Microsoft Update.exe"
- '%WINDIR%\syswow64\svchost.exe'