Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,C:\Documents and Settings\bobo.exe'
- '%WINDIR%\patch\update.exe' -u/160setup.exe
- '%TEMP%\nsj2.tmp\160yes.exe'
- '%TEMP%\nsj2.tmp\160setup.exe'
- '%WINDIR%\patch\update.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\360.dll"
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %TEMP%\892.tmp
- C:\Documents and Settings\bobo.txt
- %WINDIR%\patch\update.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\oyyy[1].exe
- %TEMP%\nsj2.tmp\160setup.exe
- %TEMP%\nsj2.tmp\160yes.exe
- <SYSTEM32>\360.dll
- %TEMP%\E_4\krnln.fnr
- %TEMP%\892.tmp
- C:\Documents and Settings\bobo.txt в C:\Documents and Settings\bobo.exe
- 'so##60.com':80
- 'localhost':1037
- so##60.com/adong/oyyy.exe
- DNS ASK so##60.com
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: ''