Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LG' = '%WINDIR%\hwupgrade.exe'
- скрытых файлов
- '%WINDIR%\hwupgrade.exe' /pid=3256
- '%WINDIR%\hwupgrade.exe' /pid=2700
- '%WINDIR%\hwupgrade.exe' /pid=728
- '%WINDIR%\hwupgrade.exe' /pid=2832
- '%WINDIR%\msncom.exe'
- '%WINDIR%\hwupgrade.exe'
- '%WINDIR%\hwupgrade.exe' (загружен из сети Интернет)
- %WINDIR%\hwupgrade.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\downcontroller[1]
- %WINDIR%\msncom.exe
- 'zv###uga.com.ua':80
- zv###uga.com.ua/downcontroller/?af####################
- DNS ASK zv###uga.com.ua