Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'safe' = '%systemroot%\system\cfmon.exe'
- '%WINDIR%\system\cfmon.exe'
- '<SYSTEM32>\net1.exe' start Browser
- '<SYSTEM32>\net1.exe' start lanmanserver
- '<SYSTEM32>\net1.exe' start lanmanworkstation
- '<SYSTEM32>\taskkill.exe' /im cfmon.exe /f
- '<SYSTEM32>\wscript.exe' "c:\112.vbe"
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\b[1].jpg
- %WINDIR%\Fonts\nsb.ini
- %WINDIR%\system\cfmon.exe
- C:\112.vbe
- <DRIVERS>\etc\hosts
- 'ht#.xorg.pl':80
- 'localhost':1036
- ht#.xorg.pl/b.jpg
- DNS ASK ht#.xorg.pl
- ClassName: '(null)' WindowName: '(null)'