Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'hao567' = '%CommonProgramFiles%\Sogou.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Devices Manager] 'Start' = '00000002'
- '%CommonProgramFiles%\Sogou.exe'
- '<SYSTEM32>\Sougou.exe'
- '%WINDIR%\Temp\ahnlab.exe'
- '%WINDIR%\Temp\m.exe'
- '<SYSTEM32>\taskkill.exe' /f /t /im iexplore.exe
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1201' = '00000000'
- %WINDIR%\Temp\m.exe
- <SYSTEM32>\Sougou.exe
- %WINDIR%\Temp\ahnlab.exe
- %WINDIR%\Temp\ahnlab.ini
- %CommonProgramFiles%\Sogou.exe
- <SYSTEM32>\Sougou.exe в %CommonProgramFiles%\Sogou.exe
- %WINDIR%\Temp\m.exe в %CommonProgramFiles%\Sogou.exe
- '10#.#1.240.10':81
- ClassName: '' WindowName: '?? ?? ??'
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''