Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = '%LOCALAPPDATA%\Microsoft\WindowsUpdater.exe'
- %LOCALAPPDATA%\microsoft\windowsupdater.exe
- %LOCALAPPDATA%\microsoft\windowsupdater.exe
- 'ra#.####ubusercontent.com':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK mo#####.map.fastly.net
- '%LOCALAPPDATA%\microsoft\windowsupdater.exe'
- '<SYSTEM32>\attrib.exe' +h %LOCALAPPDATA%\Microsoft\WindowsUpdater.exe