Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ПµНіХэіЈФЛРРІ»їЙЙЩµДЅшіМ' = '%PROGRAM_FILES%\Internet Explorer\Connection Wizard\ycmuma.exe'
- '%PROGRAM_FILES%\Internet Explorer\Connection Wizard\ycmuma.exe'
- '<SYSTEM32>\ping.exe' -n 2 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\yctxt.bat" "
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ed[1].txt
- %WINDIR%\tempyc.txt
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\ycmuma.exe
- %WINDIR%\yctxt.bat
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\ycmuma.exe
- %WINDIR%\tempyc.txt
- 'localhost':1038
- 'bb#.#lau.edu.cn':80
- bb#.#lau.edu.cn/ed.txt
- bb#.#lau.edu.cn/ip.asp
- DNS ASK bb#.#lau.edu.cn