Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp3.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\fonts\internat.vbs'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe] 'Debugger' = 'shutdown -r -t 20'
- %WINDIR%\Temp\sb.exe %WINDIR%\temp\sb.ini
- %WINDIR%\regedit.exe /s %WINDIR%\temp\ie.reg
- %WINDIR%\Temp\ie.reg
- %WINDIR%\Fonts\internat.reg
- %WINDIR%\Fonts\internat.vbs
- %WINDIR%\Temp\sb.ini
- %WINDIR%\Temp\sb.exe
- 'to###.0557vip.cn':8001
- 'localhost':1036
- DNS ASK to###.0557vip.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''