Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Update' = '"%APPDATA%\Microsoft\Windows\1042\dllhost.exe"'
- '%APPDATA%\Microsoft\Windows\1042\WmiPrvSE.exe' windows-start.servehttp.com -L -o "%APPDATA%\Microsoft\Windows\1042\start.ini"
- '%APPDATA%\Microsoft\Windows\1042\dllhost.exe'
- '%TEMP%\Adobe Creative Cloud Patch.exe'
- %TEMP%\Acknowledge -BRK-.FON
- %TEMP%\bassmod.dll
- %APPDATA%\Microsoft\Windows\1042\start.ini
- %APPDATA%\Microsoft\Windows\1042\WmiPrvSE.exe
- %TEMP%\dup2patcher.dll
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\Adobe Creative Cloud Patch.exe
- %APPDATA%\Microsoft\Windows\1042\dllhost.exe
- %APPDATA%\Microsoft\Windows\1042\start.ini
- %APPDATA%\Microsoft\Windows\1042\WmiPrvSE.exe
- %APPDATA%\Microsoft\Windows\1042\dllhost.exe
- %APPDATA%\Microsoft\Windows\1042\start.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'wi######start.servehttp.com':80
- wi######start.servehttp.com/
- DNS ASK wi######start.servehttp.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'