Техническая информация
- '%WINDIR%\Temp\tmp_ad.exe'
- '%WINDIR%\system\smss.exe'
- '<SYSTEM32>\regsvr32.exe' /s "%CommonProgramFiles%\PushWare\cpush.dll"
- %TEMP%\nsh2.tmp
- %WINDIR%\Temp\tmp_ad.exe
- %CommonProgramFiles%\PushWare\cpush.dll
- %CommonProgramFiles%\PushWare\Uninst.exe
- %WINDIR%\system\smss.exe
- %PROGRAM_FILES%\Haomake\mever.ini
- %PROGRAM_FILES%\Haomake\install.dat
- <DRIVERS>\IeDrv.sys
- %PROGRAM_FILES%\Haomake\res.dat
- <DRIVERS>\IeDrv.sys
- 'ad.#o118.cn':8080
- DNS ASK ad.#o118.cn