Техническая информация
- '%WINDIR%\SVCHOST.EXE'
- '<SYSTEM32>\net1.exe' stop SharedAccess
- '<SYSTEM32>\net1.exe' start Ndisprot
- '<SYSTEM32>\net.exe' stop SharedAccess
- %WINDIR%\Temp\OLD4.tmp
- %WINDIR%\LastGood\TMP3.tmp
- %WINDIR%\SVCHOST.EXE
- <DRIVERS>\SET5.tmp
- %WINDIR%\inf\INFCACHE.0
- <DRIVERS>\winsys.inf
- <DRIVERS>\ndissyn.sys
- %WINDIR%\inf\oem3.PNF
- %WINDIR%\inf\oem3.inf
- %WINDIR%\Temp\OLD4.tmp
- <DRIVERS>\ndissyn.sys
- %WINDIR%\inf\INFCACHE.2 в %WINDIR%\inf\OLDCACHE.000
- %WINDIR%\inf\INFCACHE.1 в %WINDIR%\inf\INFCACHE.2
- <DRIVERS>\SET5.tmp в <DRIVERS>\ndissyn.sys
- %WINDIR%\LastGood\TMP3.tmp в %WINDIR%\LastGood\system32\DRIVERS\ndissyn.sys
- 'cc.##ngak.com':9413
- 'www.ba##u.com':80
- www.ba##u.com/
- DNS ASK cc.##ngak.com
- DNS ASK www.ba##u.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''