Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\netupdate] 'Start' = '00000002'
- '%WINDIR%\ntrtm.exe' -k
- '<SYSTEM32>\net1.exe' start netupdate
- '<SYSTEM32>\ping.exe' 127.0.0.1
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\updaterc[1].aspx
- %WINDIR%\ntrtm.exe
- 'www.do###ys5.com':80
- 'localhost':1037
- www.do###ys5.com/rc/updaterc.aspx?no#################################################################
- DNS ASK www.do###ys5.com