Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qw7v4x1c4fxsq' = '"%ALLUSERSPROFILE%\svchost0\iuznffnsd.exe"'
- <SYSTEM32>\tasks\windows update check - 0x19cf045a
- [HKLM\System\CurrentControlSet\Services\SSDPSRV] 'Start' = '00000002'
- %WINDIR%\syswow64\werfault.exe
- %WINDIR%\syswow64\schtasks.exe
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- %ALLUSERSPROFILE%\svchost0\iuznffnsd.exe
- из <Полный путь к файлу> в %ALLUSERSPROFILE%\svchost0\iuznffnsd.exe
- DNS ASK windowsupdate.microsoft.com
- DNS ASK yk###ork.biz
- DNS ASK tr###jv3.biz
- DNS ASK 5g##690.biz
- DNS ASK uf###67i.biz
- DNS ASK 7g###r75.biz
- DNS ASK 87###yh4.biz
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x19CF045A" /TR "%ALLUSERSPROFILE%\svchost0\iuznffnsd.exe" /RL HIGHEST (со скрытым окном)