Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}' = ''
- '%TEMP%\软件定位(vip).exe'
- '%TEMP%\server.exe'
- '%TEMP%\wyls.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\_xr.bat" "
- %TEMP%\软件定位(vip).exe
- %TEMP%\_xr.bat
- <LS_APPDATA>\Microsoft\Windows Media\9.0\WMSDKNSD.XML
- %TEMP%\wyls.exe
- %TEMP%\server.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\SysInfo.dll
- <LS_APPDATA>\Microsoft\Windows Media\9.0\WMSDKNSD.XML
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\20095172001516650[1].wma
- %TEMP%\wyls.exe
- <LS_APPDATA>\Microsoft\Windows Media\9.0\WMSDKNS.XML.bak
- 'localhost':1039
- 'pk.##www.com':80
- 'wp#d':80
- pk.##www.com/ge_88/20095172001516650.wma?st##############################
- wp#d/wpad.dat
- wp#d/wpad.dat?Ty######
- DNS ASK pk.##www.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ListBox' WindowName: 'ZXY_ExeWL'
- ClassName: 'ListBox' WindowName: 'ZXY_DllWL'