Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Update Service' = '"C:\MyService\WindowsUpdateService.exe"'
- <SYSTEM32>\sihost.exe
- C:\myservice\windowsupdateservice.exe
- C:\myservice\log.txt
- '10#.#5.217.159':7744
- 'sz.###maogege.com':8000
- http://10#.##.217.159:7744/sz.bin via 10#.#5.217.159
- DNS ASK sz.###maogege.com
- 'C:\myservice\windowsupdateservice.exe'
- 'C:\myservice\windowsupdateservice.exe' (со скрытым окном)