Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe "<SYSTEM32>\msdrv.exe"'
- <SYSTEM32>\msdrv.exe
- %TEMP%\~DF1.tmp
- <SYSTEM32>\msdrv.exe
- '61.##8.77.111':80
- 61.##8.77.111/zsh/netfile/netfileconn.asp?co########################
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''