Техническая информация
- '<SYSTEM32>\gpupdate.exe' /force
- chrome.exe
- firefox.exe
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2101' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1407' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- %ALLUSERSPROFILE%\ntuser.pol
- <SYSTEM32>\GroupPolicy\Machine\Registry.pol
- <SYSTEM32>\GroupPolicy\gpt.ini
- 'ca######.alipaytobank.com':80
- 'ba##.#orsgate.com':80
- ca######.alipaytobank.com/msg.asp?Ui#####################################
- ba##.#orsgate.com/
- DNS ASK ca######.alipaytobank.com
- DNS ASK ba##.#orsgate.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''