Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows_Update' = '"%WINDIR%\temp\wupdater.exe"'
- %WINDIR%\Temp\wupdater.exe /f
- <SYSTEM32>\ping.exe -n 1 localhost
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\809.bat""
- %WINDIR%\809.bat
- %WINDIR%\Temp\wupdater.exe
- %WINDIR%\Temp\wupdater.exe
- 'localhost':666
- ClassName: 'Indicator' WindowName: ''