Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] 'c:\360safetray' = '%CommonProgramFiles%\taobao\cfmon.exe'
- '%CommonProgramFiles%\taobao\cfmon.exe'
- '<SYSTEM32>\net1.exe' start Browser
- '<SYSTEM32>\net1.exe' start lanmanserver
- '<SYSTEM32>\net1.exe' start lanmanworkstation
- '<SYSTEM32>\taskkill.exe' /im cfmon.exe /f
- '<SYSTEM32>\wscript.exe' "c:\339.vbe"
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\b[1].jpg
- %WINDIR%\Fonts\ntd.ini
- %CommonProgramFiles%\taobao\cfmon.exe
- C:\339.vbe
- C:\339.vbe
- <DRIVERS>\etc\hosts
- 'b.###6800.com':80
- 'localhost':1035
- b.###6800.com/b.jpg
- DNS ASK b.###6800.com
- ClassName: '' WindowName: ''