Техническая информация
- [<HKLM>\SOFTWARE\Classes\CLSID\{FAC36FAA-6F1A-0EB6-A06D-123456789abc}\Shell\Open\Command] '' = '%PROGRAM_FILES%\Internet Explorer\iexplore.exe www.776la.com'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinNTServe] 'Start' = '00000002'
- <SYSTEM32>\WinNtServer.exe
- <SYSTEM32>\reg.exe ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel /v "{"871C5380-42A0-1069-A2EA-08002B30309D"}" /t REG_DWORD /d 1 /f
- <SYSTEM32>\reg.exe ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu /v "{"871C5380-42A0-1069-A2EA-08002B30309D"}" /t REG_DWORD /d 1 /f
- <SYSTEM32>\sc.exe config UI0Detect start= disabled
- <SYSTEM32>\cmd.exe /c %WINDIR%\TEMP\_tmp28.bat
- <SYSTEM32>\sc.exe stop UI0Detect
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %WINDIR%\Temp\_tmp28.bat
- <SYSTEM32>\WinNtServer.exe
- DNS ASK te##.#aoye123.net
- 'te##.#aoye123.net':8899
- ClassName: 'MS_WINHELP' WindowName: ''