Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winsat Update' = '<LS_APPDATA>\HPQ\hpqprotect.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{adws-sdws-asgt-bet9}' = '%APPDATA%\UPDTHPP\hppupdate.exe'
- '%APPDATA%\UPDTHPP\hppupdate.exe'
- '<SYSTEM32>\schtasks.exe' /CREATE /SC HOURLY /MO 5 /TN "WPUDTE7" /ST 00:00:00 /SD 10/10/2013 /TR "%APPDATA%\UPDTHPP\hppupdate.exe"
- '<SYSTEM32>\schtasks.exe' /CREATE /SC HOURLY /MO 5 /TN "WPUDTEx" /ST 00:00:00 /SD 10/10/2013 /TR "%APPDATA%\UPDTHPP\hppupdate.exe"/RU SYSTEM
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\UPDTHPP\wn7.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\UPDTHPP\wnxp.bat" "
- %APPDATA%\UPDTHPP\wnxp.bat
- <Текущая директория>\done
- %APPDATA%\UPDTHPP\hppupdate.exe
- %APPDATA%\UPDTHPP\wn7.bat
- '80.##1.223.183':80
- 'wp#d':80
- 80.##1.223.183/~ivan/web.html?51#######
- 80.##1.223.183/~ivan/web.html?45#######
- 80.##1.223.183/~ivan/web.html?79######
- 80.##1.223.183/~ivan/web.html?66#######
- 80.##1.223.183/~ivan/web.html?11########
- 80.##1.223.183/~ivan/web.html?11#######
- wp#d/wpad.dat
- 80.##1.223.183/~ivan/web.html?65#######
- 80.##1.223.183/~ivan/web.html?70#######
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'