Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Microsoft Windows Update.lnk
- '%TEMP%\.temp01\rutserv.exe' -second
- '%TEMP%\.temp01\KNWPIsystem.exe'
- '<SYSTEM32>\schtasks.exe' /Create /RL Highest /TN "Microsoft Windows Update" /SC ONSTART /TR "%TEMP%\.temp01\KNWPIsystem.exe"
- '<SYSTEM32>\cmd.exe' /c schtasks.exe /Create /RL Highest /TN "Microsoft Windows Update" /SC ONSTART /TR "%TEMP%\.temp01\KNWPIsystem.exe"
- %TEMP%\.temp01\vp8encoder.dll
- %APPDATA%\RMS_settings\Logs\rms_log_2015-11.html
- %TEMP%\.temp01\KNWPIsystem.exe
- %TEMP%\.temp01\rutserv.exe
- %TEMP%\.temp01\vp8encoder.dll
- %TEMP%\.temp01\rutserv.exe
- %TEMP%\.temp01\KNWPIsystem.exe
- 'vk.###.##derators.id5353456.ru':80
- 'rm#####ver.tektonit.ru':563
- 'rm#####ver.tektonit.ru':5655
- http://vk.###.##derators.id5353456.ru/gate/id.php?id###################################################################
- DNS ASK vk.###.##derators.id5353456.ru
- DNS ASK rm#####ver.tektonit.ru
- ClassName: 'Shell_TrayWnd' WindowName: ''