Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'run' = '%PROGRAM_FILES%\haomake\run.exe'
- '%PROGRAM_FILES%\Haomake\smss.exe'
- '%PROGRAM_FILES%\Haomake\run.exe' /all
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\winlogon.exe
- %PROGRAM_FILES%\Haomake\pushsum.dll
- %PROGRAM_FILES%\Haomake\WinPOP.dll
- %PROGRAM_FILES%\Haomake\smss.exe
- %PROGRAM_FILES%\Haomake\log.txt
- %PROGRAM_FILES%\Haomake\list.ini
- %PROGRAM_FILES%\Haomake\svchost.exe
- %PROGRAM_FILES%\Haomake\mever.ini
- %PROGRAM_FILES%\Haomake\install.dat
- %PROGRAM_FILES%\Haomake\res.dat
- %PROGRAM_FILES%\Haomake\HookIE.dll
- %PROGRAM_FILES%\Haomake\run.exe
- 'ad.#o118.cn':80
- ad.#o118.cn/ad.php?ci##############
- DNS ASK ad.#o118.cn