Техническая информация
- <SYSTEM32>\taskkill.exe /f /t /im explorer.exe
- <SYSTEM32>\taskkill.exe /f /t /im dwm.exe
- <SYSTEM32>\shutdown.exe -r -t 30 -c "I told you not to open this , naught naught you!"
- <SYSTEM32>\taskkill.exe /f /t /im csrss.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\@CashHack.bat""
- <SYSTEM32>\taskkill.exe /f /t /im iexplorer.exe
- <SYSTEM32>\taskkill.exe /f /t /im rundll32.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmon.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\badjojo[1]
- %TEMP%\1.tmp\@CashHack.bat
- %TEMP%\1.tmp\@CashHack.bat
- 'www.se#.com':80
- 'www.he##ai.com':80
- 'www.he####school.com':80
- 'localhost':1036
- 'www.re##ube.com':80
- 'www.ba##ojo.com':80
- www.ba##ojo.com/
- www.re##ube.com/
- DNS ASK www.he##ai.com
- DNS ASK www.he####school.com
- DNS ASK www.se#.com
- DNS ASK www.re##ube.com
- DNS ASK www.ba##ojo.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''