Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'test' = '<Текущая директория>\systemm32.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\systemm32] 'Start' = '00000002'
- <SYSTEM32>\sc.exe Create systemm32 binPath= "cmd /c start <Текущая директория>\systemm32.exe" type= own type= interact start= auto
- <SYSTEM32>\cmd.exe /c ""<Текущая директория>\123.bat" "
- <Текущая директория>\123.bat
- 'hi.##idu.com':80
- 'www.ba##u.com':80
- hi.##idu.com/meilideziyoutiantang
- www.ba##u.com/
- DNS ASK hi.##idu.com
- DNS ASK www.ba##u.com
- ClassName: '' WindowName: 'okewb.exe'
- ClassName: '' WindowName: 'systemm32.exe'
- ClassName: '' WindowName: 'VVisit.exe'
- ClassName: '' WindowName: 'ClickIp.exe'
- ClassName: '' WindowName: '??????????.exe'