Техническая информация
- <SYSTEM32>\tasks\compmgmtlauncher
- <SYSTEM32>\colorcpl.exe
- <SYSTEM32>\cleanmgr.exe
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- 'ba##u.com':80
- '27.##2.101.105':5689
- '27.##2.101.105':5689
- DNS ASK ba##u.com
- '%ProgramFiles%\microsoft office\office14\winword.exe'
- '<SYSTEM32>\colorcpl.exe'
- '<SYSTEM32>\cleanmgr.exe'