Техническая информация
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://www.23##.com/?ku####
- '<SYSTEM32>\taskkill.exe' /f /t /FI "IMAGENAME eq hintww*"
- %ProgramFiles%\Internet Explorer\start.vbs
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %ProgramFiles%\Internet Explorer\start.exe
- %ProgramFiles%\Internet Explorer\start.vbs
- 'localhost':1038
- '23##.com':80
- http://www.23##.com/?ku#### via 23##.com
- DNS ASK www.23##.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%ProgramFiles%\Internet Explorer\start.vbs"
- '<SYSTEM32>\cmd.exe' /c copy /y <Полный путь к файлу> "%ProgramFiles%\Internet Explorer\start.exe"
- '<SYSTEM32>\cmd.exe' /c taskkill /f /t /FI "IMAGENAME eq hintww*"
- '<SYSTEM32>\cmd.exe' /c start iexplore.exe http://www.23##.com/?ku####