Техническая информация
- [<HKLM>\SOFTWARE\Classes\IE\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.hao123o.info'
- [<HKLM>\SOFTWARE\Classes\ur1\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.hao123o.info'
- [<HKLM>\SOFTWARE\Classes\1nk\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.hao123o.info'
- %WINDIR%\regedit.exe /s ""%TEMP%\TempIE.reg""
- <SYSTEM32>\rundll32.exe advpack.dll,DelNodeRunDLL32 %HOMEPATH%\Start Menu\Programs\Internet Explorer.lnk
- <SYSTEM32>\taskkill.exe /f /im ZhuDongFangyu.exe
- %HOMEPATH%\Desktop\.dll
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\.dll
- %TEMP%\TempIE.reg
- C:\RegTemp.txt
- %HOMEPATH%\Start Menu\.ico
- %HOMEPATH%\Start Menu\Programs\.ico
- %TEMP%\TempIE.reg
- C:\RegTemp.txt
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''