Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{DD7D4640-4444-48C0-84FD-21338366D2D4}' = ''
- <SYSTEM32>\cmd.exe /c ""<Текущая директория>\_Ms.bat" "
- <Текущая директория>\_Ms.bat
- %PROGRAM_FILES%\Internet Explorer\tray.cur
- %PROGRAM_FILES%\Internet Explorer\vbaddin.sys
- %PROGRAM_FILES%\Internet Explorer\vbaddin.tdm
- %PROGRAM_FILES%\Internet Explorer\vbaddin.sys
- 'www.sh###ongpk.com':80
- 'www.ha##23.com':80
- www.sh###ongpk.com/images/logo.gif
- www.ha##23.com/
- DNS ASK www.sh###ongpk.com
- DNS ASK www.ha##23.com
- ClassName: '' WindowName: '?????????????????? - ????????????'
- ClassName: '' WindowName: '???????? V0.6 Beta Build 0306'
- ClassName: '' WindowName: 'EtherDetect Packet Sniffer'
- ClassName: '' WindowName: 'Winsock Expert v0.6 beta 1 ?????????? E-mail:web@caozhe.com Oicq:337479'
- ClassName: '' WindowName: '????????????????.Build2005112'
- ClassName: '' WindowName: 'Uhack - 0/5000'
- ClassName: '' WindowName: 'EtherDetect Packet Sniffer - ??????????'
- ClassName: '' WindowName: 'WPE PRO'
- ClassName: 'Edit' WindowName: 'explorer.exe'
- ClassName: 'Edit' WindowName: 'taskmgr.exe'
- ClassName: '' WindowName: '?????????? V1.0 By ?????????????? QQ:21215858'
- ClassName: '' WindowName: 'MiniSniffer'
- ClassName: '' WindowName: 'WPE ??????'