Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsSecurityUpdate' = '<SYSTEM32>\svchost32.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\securityupdate.exe
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- <SYSTEM32>\svchost32.exe
- '15#.#01.193.91':443
- ClassName: 'TaskManagerWindow' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im explorer.exe >nul 2>&1