Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Servicess' = '%PROGRAM_FILES%\Windows NT\Servicess.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '系统相关启动项' = '%PROGRAM_FILES%\Internet Explorer\iexplore.exe http://www.meitianjian.com '
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Servicess] 'Start' = '00000001'
- %PROGRAM_FILES%\Internet Explorer\iedvtool2.ini
- %PROGRAM_FILES%\Internet Explorer\iecompat2.ini
- %PROGRAM_FILES%\Internet Explorer\ieproxy2.ini
- %CommonProgramFiles%\System\Services.sys
- %PROGRAM_FILES%\Internet Explorer\page.ini
- %PROGRAM_FILES%\Internet Explorer\iecompat.ini
- C:\temp.ini
- %PROGRAM_FILES%\Internet Explorer\iedvtool.ini
- %PROGRAM_FILES%\Windows NT\Servicess.exe
- %PROGRAM_FILES%\Internet Explorer\ieproxy.ini
- C:\temp.ini
- 'www.me###anjian.com':80
- www.me###anjian.com/url.txt
- DNS ASK www.me###anjian.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'