Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102438}] 'Exec' = 'http://ie.256.cc/youxi.html'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102437}] 'Exec' = 'http://ie.256.cc/taobao.html'
- '%TEMP%\svchost.exe'
- '%TEMP%\winset.exe'
- '<SYSTEM32>\schtasks.exe' /Delete /TN * /F
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- %TEMP%\svchost.exe
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\desktop.ini
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\winset.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'