Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NetBoy] 'Start' = '00000002'
- %WINDIR%\svchost.exe -start
- %WINDIR%\1_tmp.exe
- %WINDIR%\0_tmp.exe
- %WINDIR%\1_tmp.exe
- %WINDIR%\svchost.exe
- %WINDIR%\0_tmp.exe
- <SYSTEM32>\d3d8caps.dat
- 'www.sh##gbt.com':80
- www.sh##gbt.com/ip.html
- DNS ASK www.sh##gbt.com
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''