Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'produpd' = '%APPDATA%\VDI\Shared\Product Updater\produpd.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\produpd.lnk
- %APPDATA%\VDI\Shared\Product Updater\b87fa79abea17e5ce1d7ff7236be832c.exe
- %APPDATA%\VDI\Shared\Product Updater\4498904e19d4e28b7aedfb4baac49aaa.exe
- %TEMP%\nsd2.tmp
- %APPDATA%\VDI\Shared\Product Updater\b87fa79abea17e5ce1d7ff7236be832c.exe в %APPDATA%\VDI\Shared\Product Updater\monhost.exe
- %APPDATA%\VDI\Shared\Product Updater\4498904e19d4e28b7aedfb4baac49aaa.exe в %APPDATA%\VDI\Shared\Product Updater\produpd.exe