Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'bgoomain.exe' = '%PROGRAM_FILES%\baigoo\bgoomain.exe'
- '%PROGRAM_FILES%\baigoo\bgoomain.exe'
- %PROGRAM_FILES%\baigoo\baigoo1.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\baigoo2[1].ini
- %PROGRAM_FILES%\baigoo\bgoocfg.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\baigoo1[1].ini
- %PROGRAM_FILES%\baigoo\baigoo2.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\sszs_ins[1].htm
- %TEMP%\cns3.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\baigoo3[1].ini
- %PROGRAM_FILES%\baigoo\baigoo3.ini
- %PROGRAM_FILES%\baigoo\uninst.exe
- %PROGRAM_FILES%\baigoo\plugin\bgoobar\band.ini
- %PROGRAM_FILES%\baigoo\plugin\bgoobar\plugin.ini
- %TEMP%\nso2.tmp
- %PROGRAM_FILES%\baigoo\plugin\bgoobar\bgoobar.dll
- %PROGRAM_FILES%\baigoo\BGooHK.dll
- %PROGRAM_FILES%\baigoo\bgooex.dll
- %PROGRAM_FILES%\baigoo\BGooBHO.dll
- %PROGRAM_FILES%\baigoo\bgoomain.exe
- %PROGRAM_FILES%\baigoo\bgook.dll
- %TEMP%\cns3.tmp
- 'us##.baigoo.com':80
- 'do####ad.baigoo.com':80
- 'localhost':1037
- do####ad.baigoo.com/baigoo/baigoo3.ini?t=######
- us##.baigoo.com/reg/sszs_ins.htm?pa##############################################################################################################################
- do####ad.baigoo.com/baigoo/baigoo1.ini?t=######
- do####ad.baigoo.com/baigoo/baigoo2.ini?t=######
- DNS ASK us##.baigoo.com
- DNS ASK do####ad.baigoo.com