Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{ACADABAE-1101-0010-8001-00AA006D2EA8}' = ''
- '<SYSTEM32>\attrib.exe' -h -s -r -a <SYSTEM32>\delete_fuck.bat
- '%WINDIR%\sleep.exe' 1000
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -new http://www.hi##.com/music.htm
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\delete_fuck.bat
- %WINDIR%\Explorer.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\music[1].htm
- <SYSTEM32>\delete_fuck.bat
- <SYSTEM32>\xz_showad.dll
- 'www.hi##.com':80
- 'localhost':1038
- http://www.hi##.com/music.htm
- DNS ASK www.hi##.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''