Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '系统相关启动项' = '%PROGRAM_FILES%\Internet Explorer\iexplore.exe http://www.meitianjian.com '
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Servicess] 'Start' = '00000001'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\url[1].txt
- %PROGRAM_FILES%\Internet Explorer\page.ini
- %CommonProgramFiles%\System\Services.sys
- %PROGRAM_FILES%\Internet Explorer\ieproxy.ini
- %PROGRAM_FILES%\dlg.sys
- %PROGRAM_FILES%\Internet Explorer\iecompat.ini
- %PROGRAM_FILES%\Internet Explorer\iedvtool.ini
- 'www.me###anjian.com':80
- www.me###anjian.com/url.txt
- DNS ASK www.me###anjian.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'