Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '360启动项修复' = '%PROGRAM_FILES%\360启动修复.vbs'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'dlg' = '%PROGRAM_FILES%\Windows NT\Services.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '系统相关启动项' = '%PROGRAM_FILES%\Internet Explorer\iexplore.exe http://www.bb1d.com/url2.txt '
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Servicess] 'Start' = '00000001'
- %PROGRAM_FILES%\Internet Explorer\page.ini
- %PROGRAM_FILES%\Internet Explorer\ieproxy2.ini
- %PROGRAM_FILES%\Internet Explorer\iedvtool2.ini
- %PROGRAM_FILES%\360Жф¶ЇРЮёґ.vbs
- %PROGRAM_FILES%\Internet Explorer\exp.txt
- %CommonProgramFiles%\System\Services.sys
- %PROGRAM_FILES%\Internet Explorer\iedvtool.ini
- %PROGRAM_FILES%\Internet Explorer\iecompat.ini
- C:\temp.ini
- %PROGRAM_FILES%\Internet Explorer\iecompat2.ini
- %PROGRAM_FILES%\Windows NT\Services.exe
- %PROGRAM_FILES%\Internet Explorer\ieproxy.ini
- %PROGRAM_FILES%\Internet Explorer\exp.txt
- %CommonProgramFiles%\System\Services.sys
- C:\temp.ini
- 'www.bb##.com':80
- '12#.#25.114.144':80
- www.bb##.com/url2.txt
- www.bb##.com/vbs2.txt
- 12#.#25.114.144/haoecdgeunion
- 12#.#25.114.144/hao123union/
- DNS ASK www.bb##.com
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''