Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{998A88A0-A355-809B-831C-B83A80000992}] 'Exec' = 'http://www.136s.com/taobao.html'
- '%TEMP%\~nsu.tmp\Au_.exe' /S _?=%TEMP%\
- '%TEMP%\uninst.exe' /S
- '%TEMP%\Intel\uc_cnzz.exe'
- '%WINDIR%\regedit.exe' /s ie.chk
- %APPDATA%\Tencent\TencentTraveler\100\TtConf.dat
- <SYSTEM32>\taobao.ico
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsw2.tmp\UserInfo.dll
- %APPDATA%\360SE\360SE.ini
- %TEMP%\temp.ini
- %TEMP%\nsw2.tmp\System.dll
- %TEMP%\uninst.exe
- %TEMP%\Intel\ie.chk
- %TEMP%\Intel\uc_cnzz.exe
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\~DF2160.tmp
- %TEMP%\nsw2.tmp\System.dll
- %TEMP%\nsw2.tmp\UserInfo.dll
- 'localhost':1036
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'