Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'updater' = '%CommonProgramFiles%\updater\wupdater.exe'
- %CommonProgramFiles%\updater\wupdater.exe
- %CommonProgramFiles%\updater\data1.dat
- %CommonProgramFiles%\updater\data2.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mgmt[1].htm
- %CommonProgramFiles%\updater\delupdat.exe
- %CommonProgramFiles%\updater\wupdater.exe
- %CommonProgramFiles%\updater\sui.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mgmt[1].htm
- 'up####.#hunderdownloads.com':80
- up####.#hunderdownloads.com/service/mgmt.svr
- DNS ASK up####.#hunderdownloads.com