Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AutoUpdate' = '%TEMP%\perflog\service.exe'
- service.exe
- %TEMP%\perflog\service.exe
- DNS ASK ko###asaw.re
- '%TEMP%\perflog\service.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AutoUpdate /t REG_SZ /d %TEMP%\perflog\service.exe /f"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c "REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AutoUpdate /t REG_SZ /d %TEMP%\perflog\service.exe /f"
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AutoUpdate /t REG_SZ /d %TEMP%\perflog\service.exe /f