Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Configuration Manager' = '%WINDIR%\cfg32.exe'
- <SYSTEM32>\regsvr32.exe /u /s %WINDIR%\cfg32o.dll
- <SYSTEM32>\regsvr32.exe /u /s %WINDIR%\cfg32r.dll
- <SYSTEM32>\regsvr32.exe /u /s %WINDIR%\cfg32p.dll
- <SYSTEM32>\regsvr32.exe /u /s %WINDIR%\cfg32s.dll
- %WINDIR%\cfg32s.dll
- %WINDIR%\cfg32o.dll
- %WINDIR%\cfg32r.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\start[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\parent[1].asp
- %WINDIR%\cfg32p.dll
- 'www.mm##ke.com':80
- www.mm##ke.com/app/parent.asp?r=###
- www.mm##ke.com/app/start.asp?r=###
- DNS ASK www.mm##ke.com