Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsSysUpdateCheck' = '%APPDATA%\Microsoft\Windows\Libraries\Service\sysupdwin.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'WindowsSysUpdateCheck' = '%APPDATA%\Microsoft\Windows\Libraries\Service\sysupdwin.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows update.lnk
- %APPDATA%\microsoft\windows\libraries\desktopwin.ini.cache
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktopwin.ini.cache
- %APPDATA%\microsoft\windows\libraries\service\sysupdwin.exe
- %APPDATA%\microsoft\windows\libraries\service\sysupdwin.exe
- DNS ASK o4#########585344.ingest.de.sentry.io
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -NonI -W Hidden -C "$s = (New-Object -COM WScript.Shell).CreateShortcut('%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Windows Update.lnk'); $s.TargetPath = '%APPDATA%\Microsoft\... (со скрытым окном)