Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'debugger' = 'debugfile.exe'
- <SYSTEM32>\reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe" /v "debugger" /t reg_sz /d debugfile.exe /f
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hacker[1].txt
- 'ol#####231022.my3gb.com':80
- 'localhost':1036
- ol#####231022.my3gb.com/hacker.txt
- DNS ASK ol#####231022.my3gb.com
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''