Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- %TEMP%\f68e.tmp\batchfile.bat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\nzmp02rz\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\97elh4pe\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\ibr3meuv\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\whzeam5m\desktop.ini
- %TEMP%\selfdel0.bat
- %TEMP%\f68e.tmp\batchfile.bat
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\Content.IE5\desktop.ini
- 'po####.hwgeneralins.com':443
- 'po####.hwgeneralins.com':443
- DNS ASK po####.hwgeneralins.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\F68E.tmp\batchfile.bat" "
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" /v "1609" /t REG_DWORD /d 00000000 /f
- '%WINDIR%\syswow64\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' -nomerge https://portal.hwgeneralins.com
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\selfdel0.bat" " (со скрытым окном)