Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'cExplorer' = '<SYSTEM32>\Explore.exe'
- [HKLM\Software\Classes\txtfile\shell\open\command] '' = '"%WINDIR%\SysWOW64\Explore.exe" "%1"'
- [HKLM\Software\Classes\inifile\shell\open\command] '' = '"%WINDIR%\SysWOW64\Explore.exe" "%1"'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '%WINDIR%\SysWOW64\Explore.exe'
- %WINDIR%\syswow64\explore.exe
- %WINDIR%\syswow64\command.txt
- 'so##ok.net':80
- http://www.so##ok.net/softcom/wb1.txt
- DNS ASK so##ok.net
- '%WINDIR%\syswow64\explore.exe'