Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\adb.url
- '%WINDIR%\sdqlyk \dwm.exe'
- '<SYSTEM32>\net1.exe' localgroup %USERNAME%s style$ /add
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
- '<SYSTEM32>\net1.exe' user style$ www.hk##33.com /add
- %TEMP%\22c94.tmp
- %TEMP%\22a33.tmp
- %WINDIR%\sdqlyk \dwm.exe
- %WINDIR%\sdqlyk \dwm.exe
- %TEMP%\22c94.tmp
- %TEMP%\22a33.tmp
- 'r.###ne.qq.com':80
- 'localhost':1038
- 'q2#####0007.f3322.org':6000
- r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui##
- DNS ASK r.###ne.qq.com
- DNS ASK q2#####0007.f3322.org
- ClassName: '' WindowName: 'sdqlisagoodsoftware39489'