Техническая информация
- %WINDIR%\Tasks\MsUpdateTask.job
- [<HKLM>\SYSTEM\ControlSet001\Services\Schedule] 'Start' = '00000002'
- '<SYSTEM32>\rundll32.exe' /s "%WINDIR%\winse3.dll",SendStatisticDataOnInstall
- '<SYSTEM32>\rundll32.exe' /s "%WINDIR%\winse3.dll",UpdateIFEOInfo
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\winse3.dll",CloseExistedDllByRundll32 %WINDIR%\winse3.dll
- %WINDIR%\winse3.dll
- %TEMP%\nsz2.tmp
- 'to##.kaola.cn':80
- to##.kaola.cn/toolPage/toolSn.jsp
- DNS ASK to##.kaola.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''