Техническая информация
- <DRIVERS>\etc\hosts.ics
- <SYSTEM32>\COMCTL32.OCX
- <SYSTEM32>\COMDLG32.OCX
- <SYSTEM32>\MSINET.OCX
- %WINDIR%\libmySQL.dll
- %WINDIR%\msvcp120.dll
- %WINDIR%\msvcr120.dll
- %WINDIR%\Pv0jv.tmp
- %WINDIR%\Pv0jv.tmp
- <DRIVERS>\etc\hosts
- <Полный путь к файлу> в <Текущая директория>\wX3P0urOcJ.exe
- 'localhost':1039
- 'dr###rme.com':80
- 'localhost':1043
- 'ci######ongans.blogspot.com':80
- 'ce##it.com':80
- http://ci######ongans.blogspot.com/
- http://www.ce##it.com/input/ev3.5x3.dll via ce##it.com
- DNS ASK dr###rme.com
- DNS ASK ci######ongans.blogspot.com
- DNS ASK www.ce##it.com
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c icacls <DRIVERS>\etc\hosts /reset
- '<SYSTEM32>\cmd.exe' /c icacls <DRIVERS>\etc\hosts.ics /reset
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\cmd.exe' /c icacls %WINDIR%\Volume.dll /deny administrators:F
- '<SYSTEM32>\cmd.exe' /c icacls %WINDIR%\Volume.dll /deny Users:F