Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'UpdateService' = '%TEMP%\SoftUpdater.exe /update'
- '%TEMP%\SoftUpdater.exe' /begin
- %TEMP%\nsi5.tmp\IpConfig.dll
- %TEMP%\nsi5.tmp\inetcEXT2.dll
- %TEMP%\softup32.txt
- %TEMP%\nsi5.tmp\System.dll
- %TEMP%\nsq2.tmp
- %TEMP%\SoftUpdater.exe
- %TEMP%\nss4.tmp
- %TEMP%\nsi5.tmp\IpConfig.dll
- %TEMP%\nsi5.tmp\System.dll
- %TEMP%\roib.6
- %TEMP%\nsi5.tmp\inetcEXT2.dll
- %TEMP%\softup32.txt в %TEMP%\roib.6
- 'www.aw###stalls.com':80
- www.aw###stalls.com/roib/?v=###################################################
- DNS ASK www.aw###stalls.com
- ClassName: 'Shell_TrayWnd' WindowName: ''