Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{19FF6EBA-69C8-36A8-9324-2D6B10DA455C}] 'stubpath' = '<SYSTEM32>\wuapi.exe'
- %WINDIR%\syswow64\wuapi.exe
- '12#.#8.147.175':80
- http://00#.sh/1/list.txt
- DNS ASK 00#.sh
- '%WINDIR%\syswow64\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{19FF6EBA-69C8-36A8-9324-2D6B10DA455C}" /f' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{19FF6EBA-69C8-36A8-9324-2D6B10DA455C}" /f