Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonZoneCrossing' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnPostRedirect' = '00000000'
- %TEMP%\28881db86\121781.temp
- %TEMP%\28881db86\aero_link.cur
- %TEMP%\28881db86\intermediate.tis
- %TEMP%\28881db86\main.twin
- %TEMP%\28881db86\dm.dll
- %TEMP%\28881db86\Plug365New.dll
- %TEMP%\28881db86\settime.dll
- %TEMP%\28881db86\TApi.dll
- %TEMP%\28881db86\TLib.dll
- %TEMP%\28881db86\t_baibaoyun_win32.dll
- %TEMP%\2888.bat
- %TEMP%\28881db86\121781.temp
- %TEMP%\28881db86\main.twin
- %TEMP%\28881db86\intermediate.tis
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2888.bat" "
- '<SYSTEM32>\tasklist.exe' /nh /fi "pid eq 2888"
- '<SYSTEM32>\find.exe' /i "2888"
- '<SYSTEM32>\ping.exe' -n 2 127.0.0.1