Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\360setup.exe' = '%TEMP%\360setup.exe:*:Enabled:360安全中心'
- %TEMP%\3602.tmp360net.dll
- %TEMP%\!@tB6C.tmp
- %TEMP%\3603.tmpsafe505.dll
- %TEMP%\YLY1.tmp
- %TEMP%\360setup.exe
- %TEMP%\des\wpappCHS.MUI
- %TEMP%\des\wpappCHS.dll
- %TEMP%\!@tB6C.tmp
- %TEMP%\des\XOE.exe
- %TEMP%\des\wpapp.exe.manifest
- %TEMP%\des\steam.dll
- %TEMP%\YLY1.tmp
- %TEMP%\des\wpapp.exe
- %TEMP%\des\steam.MUI
- 'localhost':1042
- 'pi###.360.cn':80
- 'tp.##ft80.com':80
- 's.##0.cn':80
- http://tp.##ft80.com/tj.asp?ID########################
- http://pi###.360.cn/360safe/bd_oemwujun.cab?va#######
- http://tp.##ft80.com/tj.asp?ID##############
- http://s.##0.cn/safe/instcomp.htm?so###########################################################################
- DNS ASK st####.sipphone.com
- DNS ASK ag#.#.360.cn
- DNS ASK tr.#.360.cn
- DNS ASK pi###.360.cn
- DNS ASK s.##0.cn
- DNS ASK tp.##ft80.com
- DNS ASK st.#.360.cn
- 'tr.#.360.cn':80
- 'st.#.360.cn':3478
- 'st####.sipphone.com':3478
- ClassName: 'CabinetWClass' WindowName: 'Desktop'
- ClassName: 'CabinetWClass' WindowName: '桌面'
- ClassName: 'CabinetWClass' WindowName: '??'
- '%TEMP%\360setup.exe'
- '%TEMP%\des\XOE.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\des\run.bat" "