Техническая информация
- <SYSTEM32>\tasks\windowsupdateservice
- %LOCALAPPDATA%\microsoft\windows\update\windowsupdateservice.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<Имя файла>.exe.log
- 'li###studio.ru':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'li###studio.ru':443
- DNS ASK li###studio.ru
- DNS ASK x1.#.lencr.org
- '%LOCALAPPDATA%\microsoft\windows\update\windowsupdateservice.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Query /TN "WindowsUpdateService"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "WindowsUpdateService" /TR "%LOCALAPPDATA%\Microsoft\Windows\Update\WindowsUpdateService.exe" /SC ONLOGON /RL HIGHEST /F
- '%WINDIR%\syswow64\cmd.exe' /C start "" "%LOCALAPPDATA%\Microsoft\Windows\Update\WindowsUpdateService.exe"