Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%PROGRAM_FILES%\Internet Explorer\160yes.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe %WINDIR%\system\win.bat'
- '%WINDIR%\system\mconfig.exe'
- '%TEMP%\nsb2.tmp\160yes.exe'
- '%TEMP%\nsb2.tmp\te0_exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\system\win.bat
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\wybho.dll"
- %WINDIR%\system\mconfig.exe
- %WINDIR%\system\spec.fne
- %WINDIR%\system\internet.fne
- %PROGRAM_FILES%\Internet Explorer\160yes.exe
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %WINDIR%\system\win.bat
- %TEMP%\E_N4\krnln.fnr
- %TEMP%\nsb2.tmp\te0_exe
- %TEMP%\nsb2.tmp\160yes.exe
- %WINDIR%\system\eAPI.fne
- <SYSTEM32>\wybho.dll
- 'www.so##60.com':80
- 'www.ba##u.com':80
- www.so##60.com/1085753317/go1.txt
- www.ba##u.com/
- DNS ASK www.so##60.com
- DNS ASK www.ba##u.com
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: ''