Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /IM ggdllhost.exe /F
- '%WINDIR%\syswow64\taskkill.exe' /IM BBTalk.exe /F
- %WINDIR%\syswow64\msinet.ocx
- %WINDIR%\syswow64\mscomctl.ocx
- %WINDIR%\syswow64\comdlg32.ocx
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020111520201116\index.dat
- http://www.pe######an-kommuniti.com/
- http://ww##.####longan-kommuniti.com/
- http://d1#######stzrp.cloudfront.net/themes/saledefault.css
- http://d1#######stzrp.cloudfront.net/themes/assets/style.css
- http://c.####ingcrew.net/scripts/sale_form.js
- http://d1#######stzrp.cloudfront.net/themes/assets/skenzo.css
- http://iy###arch.com/?dn#######################################
- http://ww##.####longan-kommuniti.com/favicon.ico
- DNS ASK pe######an-kommuniti.com
- DNS ASK ww##.####longan-kommuniti.com
- DNS ASK d1#######stzrp.cloudfront.net
- DNS ASK c.####ingcrew.net
- DNS ASK iy###arch.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c TASKKILL /IM BBTalk.exe /F' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c TASKKILL /IM ggdllhost.exe /F' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c TASKKILL /IM BBTalk.exe /F
- '%WINDIR%\syswow64\cmd.exe' /c TASKKILL /IM ggdllhost.exe /F