Техническая информация
- скрытых файлов
- расширений файлов
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v HideFileExt /t reg_dword /d 00000000 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSuperHidden /t reg_dword /d 00000001 /f
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://do#####.playernow.info/down.php?ui##########
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v Hidden /t reg_dword /d 00000001 /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\down[1].php
- 'do#####.playernow.info':80
- '9.##177.cn':88
- 'localhost':1036
- 'localhost':1037
- http://do#####.playernow.info/down.php?ui##########
- DNS ASK 9.##177.cn
- DNS ASK do#####.playernow.info
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''