Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Internet_Explorer.exe' = '<SYSTEM32>\Internet_Explorer.exe'
- <SYSTEM32>\tasks\startt
- C:\autoexec.bat
- %WINDIR%\syswow64\internet_explorer.exe
- C:\01851.tmp
- 'ar######house.kinghost.net':80
- http://www.ar######house.kinghost.net/acessos/en.php
- DNS ASK ar######house.kinghost.net
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Shell DocObject View' WindowName: ''
- ClassName: 'TabWindowClass' WindowName: ''
- ClassName: 'Internet Explorer_Server' WindowName: ''
- '%WINDIR%\syswow64\schtasks.exe' /create /tn startt /tr %WINDIR%/autoexec.bat /sc onstart /ru system' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn startt /tr %WINDIR%/autoexec.bat /sc onstart /ru system