Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskmgr' = '"%APPDATA%\360Safa\taskmgr.exe" a'
- [<HKLM>\SOFTWARE\Classes\CLSID\{98745625-1234-1234-1234-1234567890AB}\Shell\Open\Command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.hao0p.com'
- %WINDIR%\Tasks\At3.job
- %WINDIR%\Tasks\At2.job
- %WINDIR%\Tasks\At1.job
- '%APPDATA%\Micrasoft\taskmgr.exe'
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %APPDATA%\360Safa\taskmgr.exe
- %APPDATA%\Tancent\system.txt
- %APPDATA%\Micrasoft\taskmgr.exe
- 'www.gu####houhuayu.cn':80
- www.gu####houhuayu.cn/CYM/tongji/count/count.asp?id##########################
- DNS ASK www.gu####houhuayu.cn
- ClassName: 'Indicator' WindowName: '(null)'