Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'System' = '{45DB27BE-2E5E-4A4F-A1DD-D71CEB97B126}'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\rundll32.exe' = '%WINDIR%\rundll32.exe:*:Enabled:rundll32'
- %WINDIR%\rundll32.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\socksret[1].php
- <Текущая директория>\A
- %WINDIR%\rundll32.exe
- <SYSTEM32>\dgflib.dll
- 'su###b00m.info':80
- 'localhost':1036
- su###b00m.info/socksret.php?ip###########################
- DNS ASK su###b00m.info