Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{DD20621B-4285-4D3F-ABDF-98AFB552ED5B}] 'Exec' = 'http://j.wauee.com/click?pid=11&mid=25796&channel=1&pt=df'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PCLook' = '<Полный путь к вирусу>'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B3F38EFC-CE02-4F11-9DB7-67C2BE490337}] 'Exec' = 'http://www.aiai123.com/taobao'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{35871651-58D1-4D0C-84CB-D0F1D0940CAA}] 'Exec' = 'http://www.aiai123.com'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E32C4654-8650-42E3-AD1C-9597BF7D32B1}] 'Exec' = 'http://www.baidu.com/index.php?tn=qdsjr_pg&ch=5'
- '%WINDIR%\regedit.exe' /s <SYSTEM32>\wbem\aiai123.reg
- firefox.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\启动 Internet Explorer 浏览器.lnk
- %HOMEPATH%\Desktop\专业导航.lnk
- <SYSTEM32>\wbem\nusin.ico
- %HOMEPATH%\Desktop\挂机锁.lnk
- <SYSTEM32>\wbem\aiai123.reg
- %TEMP%\aut5.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut2.tmp
- <SYSTEM32>\wbem\aiai.ico
- %TEMP%\aut1.tmp
- <SYSTEM32>\wbem\taobao.ico
- %TEMP%\aut3.tmp
- <SYSTEM32>\wbem\baidu.ico
- %TEMP%\aut4.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'