Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'navert.exe' = '%ProgramFiles%\Internet Explorer\navert.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexpiore.exe' = '%ProgramFiles%\Internet Explorer\iexpiore.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\Internet Explorer\navert.exe' = '%ProgramFiles%\Interne...
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\Internet Explorer\iexpiore.exe' = '%ProgramFiles%\Inter...
- '<SYSTEM32>\cmd.exe' /c ""<Текущая директория>\naver.bat" "
- %ProgramFiles%\Internet Explorer\lexpiore.exe
- <Текущая директория>\naver.bat
- %ProgramFiles%\Internet Explorer\iexpiore.exe
- %ProgramFiles%\Internet Explorer\navert.exe
- %ProgramFiles%\Internet Explorer\systeme.dll
- 'gg##ol.com':80
- http://gg##ol.com/a/iexpiore.exe
- http://gg##ol.com/a/lexpiore.exe
- http://gg##ol.com/a/navert.exe
- http://gg##ol.com/a/systeme.dll
- DNS ASK gg##ol.com