Техническая информация
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://11#.#11.111.2/CPU/online/?s=#########################################################################################################
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = '{1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = '{1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12...
- <SYSTEM32>\tmp.htm
- <SYSTEM32>\tmp.reg
- 'localhost':1038
- 'm1.##all.com':80
- http://11#.#11.111.2/CPU/online/?s=######################################################################################################### via m1.##all.com
- DNS ASK ww##.2mian.cn
- DNS ASK m1.##all.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%WINDIR%\regedit.exe' /s <SYSTEM32>\tmp.reg