Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IMsql' = '%PROGRAM_FILES%\Internet Explorer\ie6im.exe'
- '%PROGRAM_FILES%\Internet Explorer\ie6im.exe'
- '<SYSTEM32>\reg.exe' add hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v IMsql /t REG_SZ /d "%PROGRAM_FILES%\Internet Explorer\ie6im.exe" /f
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\54111.bat
- %WINDIR%\explorer.exe
- <SYSTEM32>\54111.bat
- %PROGRAM_FILES%\Internet Explorer\ie6im.exe
- %WINDIR%\IMsql.buf
- %WINDIR%\IMsql.buf
- '37#.#szzx.com':2016
- DNS ASK 37#.#szzx.com