Техническая информация
- '<SYSTEM32>\net.exe' stop bits
- '<SYSTEM32>\net.exe' stop wuauserv
- '<SYSTEM32>\net.exe' stop cryptsvc
- %TEMP%\ixp000.tmp\mu.vbs
- %TEMP%\ixp000.tmp\repairwu.cmd
- %TEMP%\ixp000.tmp\zurich.ico
- %WINDIR%\windowsupdate.log в %WINDIR%\windowsupdate.old.log__
- '<SYSTEM32>\cmd.exe' /c %TEMP%\IXP000.TMP\RepairWU.cmd
- '<SYSTEM32>\net1.exe' stop bits
- '<SYSTEM32>\net1.exe' stop wuauserv
- '<SYSTEM32>\net1.exe' stop cryptsvc
- '<SYSTEM32>\net.exe' start bits
- '<SYSTEM32>\net1.exe' start bits
- '<SYSTEM32>\net.exe' start wuauserv
- '<SYSTEM32>\net1.exe' start wuauserv
- '<SYSTEM32>\net.exe' start cryptsvc
- '<SYSTEM32>\net1.exe' start cryptsvc
- '<SYSTEM32>\cscript.exe' //b mu.vbs
- '<SYSTEM32>\wuauclt.exe' /resetauthorization /detectnow