Техническая информация
- %TEMP%\HaoXy.exe
- %TEMP%\HaoXy .exe
- C:\HaoXy.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://12#.##kankan.com/index3.html
- <SYSTEM32>\wscript.exe "C:\x5.vbs"
- %TEMP%\HaoXy .exe
- %TEMP%\HaoXy.exe
- C:\HaoXy.exe
- C:\x5.vbs
- 'hi.##idu.com':80
- hi.##idu.com/haoxy2009/blog/item/4ddb6d1d226afaff1bd576fe.html
- DNS ASK hi.##idu.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''