Техническая информация
- <SYSTEM32>\cmd.exe /c \x.bat
- <SYSTEM32>\regini.exe regset.ini
- <SYSTEM32>\reg.exe delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MemWrite" /f
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MemWrite" /f /v "DisableTaskMgr" /t REG_DWORD /d 1
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\y998[1]
- <Текущая директория>\regset.ini
- C:\x.bat
- C:\x.bat
- C:\x.bat
- <Текущая директория>\regset.ini
- 'www.y9##.net':80
- 'localhost':1039
- www.y9##.net/
- www.y9##.net/jiancewangluo.asp
- DNS ASK www.y9##.net
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''