Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Ntdfdisk] 'ImagePath' = '<DRIVERS>\ntdfdisk.sys'
- '<SYSTEM32>\cmd.exe' /c c:\emsf.bat
- '<SYSTEM32>\cmd.exe' /c c:\emsf3.bat
- '%WINDIR%\ctfmon.exe'
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\e[1].txt
- C:\tmp.dat
- C:\emsf.bat
- %WINDIR%\ctfmon.exe
- <DRIVERS>\ntdfdisk.sys
- C:\emsf3.bat
- %WINDIR%\ctfmon.exe
- C:\tmp.dat
- <DRIVERS>\ntdfdisk.sys
- 'www.zh###facai.cn':80
- 'localhost':1040
- 'www.go##le.cn':80
- http://www.zh###facai.cn/e.txt
- DNS ASK www.zh###facai.cn
- DNS ASK www.go##le.cn