Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msnmsgr.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspaint.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wordpad.exe] 'Debugger' = '%WINDIR%Update.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe] 'Debugger' = '%WINDIR%Update.exe'
- %WINDIR%update.exe
- C:\duck.wav
- C:\sorter.exe
- %WINDIR%update.exe
- 'ev####derz.ueuo.com':80
- 'er#.####webhostingarea.com':443
- http://ev####derz.ueuo.com/sorter.jpg
- 'er#.####webhostingarea.com':443
- DNS ASK ev####derz.ueuo.com
- DNS ASK er#.####webhostingarea.com
- ClassName: '' WindowName: 'Gerenciador de tareafs do Windows'