Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe %WINDIR%\Help\Help.exe'
- <SYSTEM32>\taskkill.exe /im kavsvc.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.ch######lianhuanwanhui.cn/usa.htm
- <SYSTEM32>\taskkill.exe /im kav.exe
- <SYSTEM32>\taskkill.exe /im ekrn.exe
- <SYSTEM32>\taskkill.exe /im egui.exe
- %WINDIR%\Help\Help.exe
- %WINDIR%\Help\Help.exe
- 'www.ch######lianhuanwanhui.cn':80
- 'localhost':1035
- www.ch######lianhuanwanhui.cn/down.txt
- DNS ASK www.ch######lianhuanwanhui.cn
- '<IP-адрес в локальной сети>':1036
- ClassName: '' WindowName: ''