Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '360safe' = '<SYSTEM32>\360tray.exe'
- <SYSTEM32>\360tray.exe
- <SYSTEM32>\gif.exe
- %TEMP%\E_N4\eAPI.fne
- %TEMP%\E_N4\internet.fne
- %TEMP%\E_N4\spec.fne
- <SYSTEM32>\360tray.exe
- %TEMP%\E_N4\krnln.fnr
- %TEMP%\E_N4\shell.fne
- <SYSTEM32>\gif.exe
- 'www.so##60.com':80
- 'www.ba##u.com':80
- www.so##60.com/tongji/tongji.asp?pu##################################
- www.so##60.com/wb/tian.txt
- www.ba##u.com/
- DNS ASK www.so##60.com
- DNS ASK www.ba##u.com
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''