Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- <PATH_SAMPLE>䔠3.docx
- %WINDIR% \system32\wusa.exe
- %LOCALAPPDATA%\chrome.inf
- %WINDIR% \system32\wtsapi32.dll
- %WINDIR% \system32\wtsapi32.dll
- %WINDIR% \system32\wusa.exe
- 'up####forhours.com':443
- DNS ASK up####forhours.com
- '%WINDIR% \system32\wusa.exe'
- '%LOCALAPPDATA%\chrome.inf'
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<PATH_SAMPLE>䔠3.docx"
- '<SYSTEM32>\cmd.exe' "%WINDIR% \system32\wusa.exe"
- '<SYSTEM32>\cmd.exe' %LOCALAPPDATA%\chrome.inf