Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'vmtune' = 'gdlib.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe' http://1a##.com/user1.php
- %WINDIR%\syswow64\gdlib.exe
- '1a##.com':80
- http://1a##.com/user1.php
- DNS ASK 1a##.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles%\internet explorer\iexplore.exe' http://1a##.com/user1.php' (со скрытым окном)