Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,'
- '<SYSTEM32>\rundll32.exe' fldrclnr.dll,Wizard_RunDLL
- '<SYSTEM32>\cmd.exe' /c %TEMP%\rar.tmp x -y -pFZT0QvoJ!whpZ4cG -o"C:\SysBoot\" <Текущая директория>\install.tmp
- '%TEMP%\rar.tmp' x -y -pFZT0QvoJ!whpZ4cG -o"C:\SysBoot\" <Текущая директория>\install.tmp
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\cmd.exe' /c taskkill /im explorer.exe /f© <SYSTEM32>\cmmm.tmp %WINDIR%\explorer.exe /y
- '<SYSTEM32>\taskkill.exe' /im explorer.exe /f
- '<SYSTEM32>\cmd.exe' /c explorer
- %WINDIR%\Explorer.EXE
- 360tray.exe
- <SYSTEM32>\proctexe.ocx.new
- <SYSTEM32>\lmrt.dll.new
- <SYSTEM32>\dllcache\proctexe.ocx.new
- <SYSTEM32>\dllcache\lmrt.dll.new
- %TEMP%\rar.tmp
- %TEMP%\aut1.tmp
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\启动 Internet Explorer 浏览器.lnk
- %WINDIR%\Fonts\InstallLog.ini
- <SYSTEM32>\proctexe.ocx
- <SYSTEM32>\lmrt.dll
- %TEMP%\aut1.tmp
- DNS ASK www.ba##u.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'CSCHiddenWindow' WindowName: ''
- ClassName: 'BaseBar' WindowName: 'ChanApp'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''