Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,C:\Documents and Settings\baidu.exe'
- %WINDIR%\patch\update.exe -u/160setup.exe
- %TEMP%\nsl2.tmp\setup6.exe
- %TEMP%\nsl2.tmp\160setup.exe
- %WINDIR%\patch\update.exe (загружен из сети Интернет)
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\360soft.dll"
- %TEMP%\220.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\oyyy[1].exe
- C:\Documents and Settings\baidu.txt
- %WINDIR%\patch\update.exe
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %TEMP%\nsl2.tmp\160setup.exe
- %TEMP%\nsl2.tmp\setup6.exe
- <SYSTEM32>\360soft.dll
- %TEMP%\E_4\krnln.fnr
- %TEMP%\220.tmp
- C:\Documents and Settings\baidu.txt в C:\Documents and Settings\baidu.exe
- 'so##60.com':80
- 'localhost':1036
- so##60.com/adong/oyyy.exe
- DNS ASK so##60.com
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: ''