Техническая информация
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://www.ba##u56.com
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://www.ch##07.cn
- %HOMEPATH%\Favorites\░┘╢╚╙щ└╓═°╓╖╡╝║╜.url
- %HOMEPATH%\Favorites\░┘╢╚╙щ└╓═°┬ч╡ч╩╙.url
- %HOMEPATH%\Favorites\═°┬ч╙к╧·╚э╝■╧┬╘╪╒╛.url
- %TEMP%\baidu56.bat
- %TEMP%\exe1.tmp
- 'ch##07.cn':80
- 'ba##u56.com':80
- 'localhost':1036
- 'localhost':1037
- http://www.ba##u56.com/ via ba##u56.com
- http://www.ch##07.cn/ via ch##07.cn
- DNS ASK www.ba##u56.com
- DNS ASK www.ch##07.cn
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://www.ba##u56.com" /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d "http://www.ba##u56.com" /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\baidu56.bat""
- '<SYSTEM32>\reg.exe' del "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /f