Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%WINDIR%.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe %WINDIR%.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%.exe'
- '%WINDIR%.exe'
- %TEMP%\2B2C1EE.res
- %WINDIR%.exe
- <SYSTEM32>\xilehlp.dll
- <SYSTEM32>\xulehlp.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\yy[1]
- %TEMP%\2B2C1EE.res
- '12#.#25.114.144':80
- 'yy.com':80
- 'localhost':1037
- 12#.#25.114.144/dbnofydpftbatzd/item/f7929a1ad633eb7ae65e063e
- 12#.#25.114.144/dbnofydpftbatzd/item/e615db27e7b0e9b5ae48f53a
- yy.com/
- 12#.#25.114.144/dbnofydpftbatzd/item/9cdd9fdcc1b6e727d80e4444
- DNS ASK hi.##idu.com
- DNS ASK yy.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''