Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\WinDefendUpdater] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinDefendUpdater] 'ImagePath' = 'cmd.exe /c start /min "" "%ALLUSERSPROFILE%\Microsoft\WindowsUpdate\svchost.exe"'
- 'WinDefendUpdater' cmd.exe /c start /min "" "%ALLUSERSPROFILE%\Microsoft\WindowsUpdate\svchost.exe"
- <SYSTEM32>\cmd.exe
- %ALLUSERSPROFILE%\microsoft\windowsupdate\svchost.exe
- 'ra###group.vip':443
- 'ra###group.vip':443
- DNS ASK ra###group.vip
- '%ALLUSERSPROFILE%\microsoft\windowsupdate\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c start /min "" "%ALLUSERSPROFILE%\Microsoft\WindowsUpdate\svchost.exe"