Техническая информация
- %WINDIR%\syswow64\sanv\bho.dll
- %WINDIR%\syswow64\sanv\client.vbs
- %WINDIR%\syswow64\sanv\iadconfig.ini
- %WINDIR%\syswow64\sanv\krnln.fne
- %WINDIR%\syswow64\sanv\svchost.exe
- %WINDIR%\syswow64\sanv\bho.bat
- %TEMP%\tmp.reg
- %WINDIR%\syswow64\sanv\iehelper.dll
- %WINDIR%\iadgame.log
- %WINDIR%\iad.ini
- %TEMP%\tmp.reg
- DNS ASK do####l.jiajiaee.cn
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\sanv\svchost.exe'
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\sanv\Client.vbs"
- '%WINDIR%\syswow64\cmd.exe' /C <SYSTEM32>\sanv\bho.bat (со скрытым окном)
- '%WINDIR%\syswow64\regedit.exe' /s "%TEMP%\tmp.reg"
- '%WINDIR%\syswow64\regsvr32.exe' /s bho.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s <SYSTEM32>\sanv\IEHELPER.dll