Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicroSoftUpdate' = '%TEMP%\svshost.exe'
- '%TEMP%\sqlwriter.exe'
- '%TEMP%\svshost.exe'
- '<SYSTEM32>\cmd.exe' /c temp.bat
- '<SYSTEM32>\ipconfig.exe' /flushdns
- <SYSTEM32>\ctfmon.exe
- iexplore.exe
- firefox.exe
- chrome.exe
- %HOMEPATH%\temp.bat
- %TEMP%\sqlwriter.exe
- %TEMP%\TMP654.dll
- %APPDATA%\check.txt
- %TEMP%\svshost.exe
- %TEMP%\svshost.exe
- %HOMEPATH%\temp.bat