Техническая информация
- [<HKLM>\Software\Classes\CLSID\{86AEFBE8-763F-0647-899C-A93278894D8E}\Shell\Open\Command] '' = '%ProgramFiles%\Internet Explorer\Iexplore.exe http://6071.com/?ii'
- '%ProgramFiles%\internet explorer\iexplore.exe' http://yo##1.com/?tt
- 'localhost':5152
- DNS ASK yo##1.com
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath xfThZRQKpE1U6h00fnWMXYF5DkXYyL+O