Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IEProtector' = '%PROGRAM_FILES%\IEProtector\ieprotector.exe hide,start'
- [<HKLM>\SYSTEM\ControlSet001\Services\IEProtector] 'Start' = '00000002'
- %PROGRAM_FILES%\IEProtector\IEProtector.exe hide,init
- %PROGRAM_FILES%\Messenger\spuku.exe
- %PROGRAM_FILES%\Messenger\setup_10035.exe
- %PROGRAM_FILES%\IEProtector\TaoBao.exe
- %PROGRAM_FILES%\IEProtector\uninst.exe
- %PROGRAM_FILES%\IEProtector\uninstall.dat
- %PROGRAM_FILES%\IEProtector\IEService.exe
- %TEMP%\nsm2.tmp\System.dll
- %PROGRAM_FILES%\IEProtector\App.ini
- %PROGRAM_FILES%\IEProtector\IEProtector.exe
- %HOMEPATH%\Start Menu\Programs\IEProtector\IEКШ»¤ХЯ.lnk
- %TEMP%\nso4.tmp\System.dll
- %TEMP%\nso4.tmp\SimpleSC.dll
- %HOMEPATH%\Start Menu\Programs\IEProtector\Р¶ФШIEКШ»¤ХЯ.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\123[1]
- %HOMEPATH%\Start Menu\IEКШ»¤ХЯ.lnk
- %HOMEPATH%\Desktop\МФ±¦ПЮК±ГлЙ±.lnk
- %TEMP%\null\Setup_10000.exe
- %TEMP%\$inst\temp_0.tmp
- %PROGRAM_FILES%\Messenger\setup_10035.exe
- %PROGRAM_FILES%\Messenger\УОП·Нв№Т№ЩНшµјєЅ.url
- %TEMP%\$inst\15.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\4.tmp
- %TEMP%\$inst\5.tmp
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МЪС¶QQ.lnk
- %HOMEPATH%\Desktop\УОП·Нв№Т№ЩНшµјєЅ.lnk
- %HOMEPATH%\Favorites\УОП·Нв№Т№ЩНшµјєЅ.lnk
- %HOMEPATH%\Desktop\МЪС¶QQ.lnk
- %PROGRAM_FILES%\Messenger\QQUnist.exe
- %PROGRAM_FILES%\Messenger\MQ.ico
- %PROGRAM_FILES%\Messenger\spuku.exe
- %TEMP%\nso4.tmp\System.dll
- %TEMP%\nso4.tmp\SimpleSC.dll
- %TEMP%\nsm2.tmp\System.dll
- %TEMP%\null\setup_10035.exe
- %TEMP%\$inst\15.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\5.tmp
- %TEMP%\$inst\4.tmp
- 'tj.###uanjia.com':85
- 'www.17##5.info':80
- 'localhost':1037
- www.17##5.info/123/?00#
- DNS ASK tj.###uanjia.com
- DNS ASK www.17##5.info
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''