Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1402' = '00000000'
- <PATH_SAMPLE>.log
- <Текущая директория>\user.txt
- <PATH_SAMPLE>.ini
- 'ip.##haha.cn':80
- http://ip.##haha.cn//gorun.exe
- http://ip.##haha.cn//click.exe
- http://ip.##haha.cn//update.txt
- http://ip.##haha.cn//pvgo.asp?Оґ####################
- DNS ASK ip.##haha.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Полный путь к файлу>"