Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{DD7D4640-4444-48C0-84FD-21338366D2D4}' = ''
- '<SYSTEM32>\cmd.exe' /c ""<Текущая директория>\_Ms.bat" "
- <Текущая директория>\_Ms.bat
- %PROGRAM_FILES%\Internet Explorer\tray.cur
- %PROGRAM_FILES%\Internet Explorer\vbaddin.sys
- %PROGRAM_FILES%\Internet Explorer\vbaddin.tdm
- %PROGRAM_FILES%\Internet Explorer\vbaddin.sys
- 'www.ha##23.com':80
- www.ha##23.com/
- DNS ASK www.ha##23.com
- ClassName: 'Edit' WindowName: 'explorer.exe'
- ClassName: 'Edit' WindowName: 'taskmgr.exe'