Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'safe' = '%systemroot%\system\cfmon.exe'
- '%WINDIR%\system\cfmon.exe'
- '<SYSTEM32>\wscript.exe' "c:\338.vbe"
- '<SYSTEM32>\taskkill.exe' /im cfmon.exe /f
- C:\338.vbe
- %WINDIR%\system\cfmon.exe
- <DRIVERS>\etc\hosts
- 'localhost':1035
- DNS ASK b.###6800.com
- ClassName: '(null)' WindowName: '(null)'