Техническая информация
- <SYSTEM32>\attrib.exe +s +h "%userprofile%\桌面\Internet Explorer.*"
- <SYSTEM32>\rundll32.exe user32.DLL, UpdatePerUserSystemParameters
- <SYSTEM32>\reg.exe DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{00000000-0000-0000-0000-000000000009}" /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qdata[1].asp
- 'da##.#ongbing.com':80
- 'localhost':1037
- da##.#ongbing.com/test/qdata.asp?1=#########################
- DNS ASK da##.#ongbing.com
- '<IP-адрес в локальной сети>':1038
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''