Техническая информация
- скрытых файлов
- расширений файлов
- '<SYSTEM32>\cmd.exe' /c attrib -s -h -r "%HOMEPATH%\Desktop\*.exe"
- '<SYSTEM32>\attrib.exe' -s -h -r "%HOMEPATH%\Desktop\*.exe"
- '<SYSTEM32>\cmd.exe' /c del /f/a/q "%HOMEPATH%\Desktop\*.exe"
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSuperHidden /t reg_dword /d 00000001 /f
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v Hidden /t reg_dword /d 00000001 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v HideFileExt /t reg_dword /d 00000000 /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\go6000[1]
- 'www.go##00.com':80
- 'localhost':1037
- http://www.go##00.com/?wo
- DNS ASK www.go##00.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''