Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102438}] 'Exec' = 'http://ie.256.cc/youxi.html'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102437}] 'Exec' = 'http://ie.256.cc/taobao.html'
- '<SYSTEM32>\schtasks.exe' /Delete /TN * /F
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\desktop.ini
- ClassName: 'Indicator' WindowName: '(null)'