Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Windows Updaing' = '%PROGRAM_FILES%\toshiba.exe'
- 'C:\systemp.sys'
- 'C:\systemp.sys' (загружен из сети Интернет)
- '<SYSTEM32>\taskkill.exe' /F /IM cmd.exe
- '<SYSTEM32>\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run" /V "Windows Updaing" /D "%PROGRAM_FILES%\toshiba.exe" /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\%77%69%6E%75%70%64%61%74%65%73[1].htm
- C:\systemp.sys
- %PROGRAM_FILES%\toshiba.exe
- C:\systemp.sys
- 'up#####windows.uv.ro':80
- 'localhost':1036
- up#####windows.uv.ro/%77%69%6E%75%70%64%61%74%65%73.htm
- DNS ASK up#####windows.uv.ro
- ClassName: '' WindowName: ''