Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systemup' = '"%WINDIR%\systemup.exe" stand'
- %WINDIR%\systemup.exe stand
- <SYSTEM32>\netstat.exe -ano
- <SYSTEM32>\taskkill.exe /F /IM systemup.exe
- %WINDIR%\systemup.exe
- '18#.#5.218.165':62999
- '31.##.150.159':62999
- '62.##.172.72':62999
- '88.##7.23.242':62999
- '82.##5.65.145':62999
- '62.##.198.216':62999
- '46.##.73.188':62999
- '17#.#07.38.52':62999
- '20#.#26.126.176':62999
- '89.##.183.19':62999
- '46.##.50.185':62999
- 'yo##ube.com':80
- '11.#1.11.11':55611
- '79.##9.110.198':62999
- '92.#14.3.78':62999
- '66.##9.247.150':62999
- '19#.#.236.39':62999
- yo##ube.com/
- DNS ASK yo##ube.com
- ClassName: '' WindowName: ''