Техническая информация
- Cредство проверки системных файлов (SFC)
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v RegisteredOrganization /t reg_sz /d б╛╢л╨╦═°╓┌═°╬мб┐ /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v RegisteredOwner /t reg_sz /d б╛╟╒╓▌╧╚╖цб┐ /f
- '<SYSTEM32>\attrib.exe' "<DRIVERS>\etc\hosts" +R
- '<SYSTEM32>\cmd.exe' /c <DRIVERS>\i8del.bat
- '<SYSTEM32>\attrib.exe' "<DRIVERS>\etc\hosts" -H -R
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000000'
- <SYSTEM32>\mms.cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\2345[1]
- <DRIVERS>\i8del.bat
- <SYSTEM32>\Macromed\Flash\mms.cfg
- 'www.23##.com':80
- 'localhost':1038
- www.23##.com/?k1#######
- DNS ASK v.##45.com
- DNS ASK www.23##.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''