Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%PROGRAM_FILES%\Internet Explorer\160yes04.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe %WINDIR%\system\win.bat'
- %WINDIR%\system\mconfig.exe
- %TEMP%\nsp2.tmp\160yes04.exe
- %TEMP%\nsp2.tmp\te0_exe
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\wybho.dll"
- <SYSTEM32>\cmd.exe /c %WINDIR%\system\win.bat
- %WINDIR%\system\win.bat
- %WINDIR%\system\mconfig.exe
- %WINDIR%\system\spec.fne
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\tongji[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\go1[1].txt
- %PROGRAM_FILES%\Internet Explorer\160yes04.exe
- %TEMP%\E_N4\krnln.fnr
- %TEMP%\nsp2.tmp\te0_exe
- %TEMP%\nsp2.tmp\160yes04.exe
- %WINDIR%\system\internet.fne
- <SYSTEM32>\wybho.dll
- %WINDIR%\system\eAPI.fne
- 'www.so##60.com':80
- 'www.ba##u.com':80
- www.so##60.com/1085753317/tongji1/tongji.asp?pu##################################
- www.so##60.com/1085753317/go1.txt
- www.ba##u.com/
- DNS ASK www.so##60.com
- DNS ASK www.ba##u.com
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: ''