Техническая информация
- [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '"%PROGRAM_FILES%\baidu\BaiduBrowser\BaiduBrowser.exe" -- "%1"'
- [<HKLM>\SOFTWARE\Classes\ftp\shell\open\command] '' = '"%PROGRAM_FILES%\baidu\BaiduBrowser\BaiduBrowser.exe" -- "%1"'
- [<HKLM>\SOFTWARE\Classes\https\shell\open\command] '' = '"%PROGRAM_FILES%\baidu\BaiduBrowser\BaiduBrowser.exe" -- "%1"'
- [<HKLM>\SOFTWARE\Classes\BaiduBrowserHTML\shell\open\command] '' = '"%PROGRAM_FILES%\baidu\BaiduBrowser\BaiduBrowser.exe" -- "%1"'
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\BaiduBrowser.EXE\shell\open\command] '' = '"%PROGRAM_FILES%\baidu\BaiduBrowser\BaiduBrowser.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\bluebox] 'Start' = '00000001'
- '%PROGRAM_FILES%\baidu\BaiduBrowser\baidubrowser.exe' --type=UtilProcess --Action=SetDefault
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe' --checkbrowser2
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe' --getdefaultbrowser
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdupdate.exe' --frominstall
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe' --reportsetbaidudefault --info=1
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe' --fixbaidu_default
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdupdate.exe' --clear_audata
- '%TEMP%\bdbrowser_setup_mini-19095018_676-4_7_0_1908-5523'
- '%PROGRAM_FILES%\BlueBox\BlueBox.exe' hide
- '%TEMP%\BlueBox_<Имя вируса>_S_Setup' /S
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe' --version=2.0 --func=0x21 --statval="InstallType=-E&Version=2.190.0.1908&From=19095018_676&OneKeyEvent=FileReady"
- '%PROGRAM_FILES%\baidu\BaiduBrowser\bddataconverter.exe' --action=convertall
- '%TEMP%\bdbrowserutil\bdutil.exe' --version=2.0 --func=0x21 --statval="InstallType=-E&Version=2.190.0.1908&From=19095018_676&OneKeyEvent=Started&NeedUserInfo=true"
- NtEnumerateValueKey, драйвер-обработчик: bluebox.sys
- NtQueryValueKey, драйвер-обработчик: bluebox.sys
- NtSetValueKey, драйвер-обработчик: bluebox.sys
- NtDeleteKey, драйвер-обработчик: bluebox.sys
- NtDeleteValueKey, драйвер-обработчик: bluebox.sys
- NtEnumerateKey, драйвер-обработчик: bluebox.sys
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\TaobaoCustomFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\TaobaoCustomThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\SinaFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\SinaThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Tecent.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Tecent.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\TaobaoFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\TaobaoThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\SinaCustomThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Hao123CustomThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\NavigatorFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BrowserTiebaFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Hao123CustomFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\RenrenFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\SinaCustomFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\NavigatorThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Renren.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\tudou.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\tv.sohu.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\letv.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\lol.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\bookmark_v2
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\cookie.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\appmgr.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\appstoragemgr.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\ku6.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Youku.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\Youku.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\WeiboFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\WeiboThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\iqiyi.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\kankan.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\dnf.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\duowan.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BrowserHomeThumbnail.jpg
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\appmgr.db
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\appstoragemgr.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\msvcp100.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\msvcr100.dll
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\downloadmgr.db
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\history.db
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\bookmark_v2
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\cookie.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\bddataconverter.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdstorage.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdutil.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdstartlogic.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdaccount.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdcrashreport.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdcrashreport.ini
- %PROGRAM_FILES%\baidu\BaiduBrowser\sqlite3.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdminiopenssl.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\7k7k.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BaiduCustomFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\4399.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\56.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BaiduThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BrowserHomeFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BaiduCustomThumbnail.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\BaiduFavIcon.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\local\3636.ico
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\ExtApp\update.zip
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\fewl.dat
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\tieba_bookmark_v2
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079550052004e00580059004d0041005600\ExtApp\extapp.json
- %APPDATA%\Baidu\browser\extConvert.log
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\feext.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\ftp2html.html
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\extension\dir_header.html
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdxmppclient.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdxmppclient.ini
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdmessui.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdmainui.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bddownload.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\xnet.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdsyncclient.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdsyncclient.ini
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdxui.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdupdate.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\baidubrowser.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Theme\Thumbnails\default.jpg
- %PROGRAM_FILES%\baidu\BaiduBrowser\topsites.json
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdstartui.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdicebreaker.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\uninst.exe
- %PROGRAM_FILES%\baidu\BaiduBrowser\browsercore.dll
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\百度浏览器.lnk
- %HOMEPATH%\Start Menu\Programs\百度浏览器.lnk
- %APPDATA%\Baidu\browser\config.ini
- %HOMEPATH%\Desktop\百度浏览器.lnk
- %ALLUSERSPROFILE%\Application Data\Baidu\BaiduBrowserGA\AutoUpdate\updatelog\autoupdate_20140611164818_3380.log
- %ALLUSERSPROFILE%\Application Data\Baidu\BaiduBrowserGA\AutoUpdate\updatelog\autoupdate_20140611164832_3756.log
- %ALLUSERSPROFILE%\Start Menu\Programs\百度浏览器\百度浏览器.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\百度浏览器\百度浏览器(无痕窗口).lnk
- %PROGRAM_FILES%\baidu\BaiduBrowser\18ec850dfaf2f945a6b9d75134d4e20c
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdupdate.ini
- %PROGRAM_FILES%\baidu\BaiduBrowser\pk.pem
- %PROGRAM_FILES%\baidu\BaiduBrowser\funoffset.ini
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdstatreport.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdmsiecore.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\files.md5
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdlogicmain.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\atl100.dll
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\tipstr.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\imageupload.bmp
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\imagecloudalbum.bmp
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\NewTabLogo.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\hao123.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\folder_open.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\logo.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ImageSearch.bmp
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\folder.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\blank.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\tieba_bookmark_v2
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\ExtApp\extapp.json
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\downloadmgr.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\history.db
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Skin\FirstSkin\skin.zip
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\logo.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\UserData\ExtApp\update.zip
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Skin\FirstSkin\main.zip
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\refresh2.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\bkglb.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\head.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\refresh.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\bkgrt.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\close.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\bkglt.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\desktoptip\bkgrb.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\errorPage.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\CloudTreeCtrl\folder.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\CloudTreeCtrl\root.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\my_folder.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\TreeCtrl\net_folder.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\baidu.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\ErrorPage\baidu2.png
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\FavoBar\favobar_folder.ico
- %PROGRAM_FILES%\baidu\BaiduBrowser\resource\application\Image\FavoBar\favobar_blanklogo.ico
- %PROGRAM_FILES%\BlueBox\res_bluebox\roundbk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\scroll_bkgnd.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\prompt.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\refresh.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\topbk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\topright.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\scroll_thumb.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\success.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\progress_textbk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\groupcapbk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\grouptop.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\fail.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\frame.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\progress_bk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\progress_fore.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\listtop.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\logo.png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bluebox[1].html
- %HOMEPATH%\Start Menu\Programs\蓝光宝盒\蓝光宝盒.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\install[1].1&softid=0&hid=11000000000000000001&macadd=00-00-00-00-00-01&md5=5E8CF0724013AA9F5A143908FC6B6709&rand=217546
- %APPDATA%\BlueBox\soft_installed.xml
- %TEMP%\nsn6.tmp\CloseRun2.dll
- %TEMP%\bdbrowserskinres\AnNiu.png
- %HOMEPATH%\Start Menu\Programs\蓝光宝盒\卸载 蓝光宝盒.lnk
- %TEMP%\nsg5.tmp
- %PROGRAM_FILES%\BlueBox\bbfixer.exe
- %PROGRAM_FILES%\BlueBox\res_bluebox\wait.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\warning.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\topright_bk.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\wait.gif
- %APPDATA%\BlueBox\list_soft.xml
- %PROGRAM_FILES%\BlueBox\setting.ini
- %PROGRAM_FILES%\BlueBox\res_bluebox\xuanqu_img1.png
- %APPDATA%\BlueBox\config_update.xml
- %PROGRAM_FILES%\BlueBox\res_bluebox\editbk.png
- %PROGRAM_FILES%\BlueBox\bbcomm.dll
- %PROGRAM_FILES%\BlueBox\bbhelper.dll
- %PROGRAM_FILES%\BlueBox\bluebox.sys
- %PROGRAM_FILES%\BlueBox\BlueBox.exe
- %PROGRAM_FILES%\BlueBox\install.ico
- %PROGRAM_FILES%\BlueBox\license.txt
- %PROGRAM_FILES%\BlueBox\dsui.dll
- %PROGRAM_FILES%\BlueBox\hgcounter.dll
- %TEMP%\setupplugins.dll
- %TEMP%\bdbrowser_setup_mini-19095018_676-4_7_0_1908-5523
- %TEMP%\list_soft.xml
- C:\BlueSoftSetup.log
- %TEMP%\BlueBox_bsdlwx_S_Setup
- %TEMP%\nsx3.tmp\System.dll
- %PROGRAM_FILES%\BlueBox\install.log
- %TEMP%\BlueBox_<Имя вируса>_S_Setup
- %TEMP%\nsc2.tmp
- %PROGRAM_FILES%\BlueBox\res_bluebox\btnbk3.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\btnbk4.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\btnbk2.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\btnbk2_old.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\deficon.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\dividing_line.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\checkbox.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\corner.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\btnbk1.png
- %PROGRAM_FILES%\BlueBox\setupplugins.dll
- %PROGRAM_FILES%\BlueBox\statmgr.dll
- %PROGRAM_FILES%\BlueBox\main.ico
- %PROGRAM_FILES%\BlueBox\selfdestructor.bat
- %PROGRAM_FILES%\BlueBox\res_bluebox\arrow.png
- %PROGRAM_FILES%\BlueBox\res_bluebox\bottombk.png
- %PROGRAM_FILES%\BlueBox\uninst.exe
- %PROGRAM_FILES%\BlueBox\uninst.ico
- %TEMP%\bdbrowserskinres\progress_fail.png
- %TEMP%\bdbrowserskinres\rolling_map.png
- %TEMP%\bdbrowserskinres\progress.png
- %TEMP%\bdbrowserskinres\progress_bg.png
- %TEMP%\bdbrowserskinres\Licence.txt
- %TEMP%\bdbrowserskinres\skin.txt
- %TEMP%\bdbrowserskinres\sad.png
- %TEMP%\bdbrowserskinres\title.png
- %TEMP%\bdbrowserskinres\logo_16.png
- %TEMP%\bdbrowserskinres\btn_small.png
- %TEMP%\bdbrowserskinres\button-blue.png
- %TEMP%\bdbrowserskinres\btn_min_alpha.png
- %TEMP%\bdbrowserskinres\btn_min_custm.png
- %TEMP%\bdbrowserskinres\loading_repair.png
- %TEMP%\bdbrowserskinres\logo.png
- %TEMP%\bdbrowserskinres\happy.png
- %TEMP%\bdbrowserskinres\loading3.png
- %APPDATA%\Baidu\browser\ClientStat\Path_browserutil\statfailed_v2.xml
- %APPDATA%\Baidu\browser\ClientStat\Path_browserutil\statcount_v2.xml
- %TEMP%\bdbrowsersetup\DefaultConfig.xml
- %PROGRAM_FILES%\baidu\BaiduBrowser\browserconfig
- %APPDATA%\Baidu\browser\ClientStat\Path_browserutil\statnoncover_v2.xml
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdcommon.dll
- %APPDATA%\Baidu\browser\ClientStat\Path_browserutil\statcover_v2.xml
- %PROGRAM_FILES%\baidu\BaiduBrowser\bdlog.dll
- %TEMP%\bdbrowserutil\msvcr100.dll
- %TEMP%\nsn6.tmp\System.dll
- %TEMP%\nsn6.tmp\UserInfo.dll
- %TEMP%\bdbrowserskinres\unskin.txt
- %TEMP%\nsn6.tmp\nsSkinEngine.dll
- %TEMP%\bdbrowserutil\bdcommon.dll
- %TEMP%\bdbrowserutil\msvcp100.dll
- %TEMP%\bdbrowserutil\bdutil.exe
- %TEMP%\bdbrowserutil\bdstatreport.dll
- %TEMP%\bdbrowserskinres\btn_min2.png
- %TEMP%\bdbrowserskinres\FenGeXian.png
- %TEMP%\bdbrowserskinres\GuanBi.png
- %TEMP%\bdbrowserskinres\DuoXuan.png
- %TEMP%\bdbrowserskinres\DuoXuanDisable.png
- %TEMP%\bdbrowserskinres\LogoXuanChuanTu.png
- %TEMP%\bdbrowserskinres\TanChuKuangDiTu.png
- %TEMP%\bdbrowserskinres\JinDuTiaoDitu.png
- %TEMP%\bdbrowserskinres\JinDuTiaoYouJinDu.png
- %TEMP%\bdbrowserskinres\DuoXuan - o,.png
- %TEMP%\bdbrowserskinres\AnZhuangXuanChuanTu1.png
- %TEMP%\bdbrowserskinres\AnZhuangXuanChuanTu2.png
- %TEMP%\bdbrowserskinres\AnNiu2.png
- %TEMP%\bdbrowserskinres\AnNiuJiaoDian.png
- %TEMP%\bdbrowserskinres\DanXuan.png
- %TEMP%\bdbrowserskinres\DiBu.png
- %TEMP%\bdbrowserskinres\AnZhuangXuanChuanTu3.png
- %TEMP%\bdbrowserskinres\BeiJing.png
- %TEMP%\bdbrowserskinres\btn_big.png
- %TEMP%\bdbrowserskinres\btn_close.png
- %TEMP%\bdbrowserskinres\bg_mb.png
- %TEMP%\bdbrowserskinres\bg_normal.png
- %TEMP%\bdbrowserskinres\btn_close_custm.png
- %TEMP%\bdbrowserskinres\btn_min.png
- %TEMP%\bdbrowserskinres\btn_close2.png
- %TEMP%\bdbrowserskinres\btn_close_alpha.png
- %TEMP%\bdbrowserskinres\bg_logo_backup.png
- %TEMP%\bdbrowserskinres\TanHao.png
- %TEMP%\bdbrowserskinres\ZuiXiaoHua.png
- %TEMP%\bdbrowserskinres\TanChuKuangDiTu2.png
- %TEMP%\bdbrowserskinres\TanChuKuangGuanBi.png
- %TEMP%\bdbrowserskinres\bg.png
- %TEMP%\bdbrowserskinres\bg_logo.png
- %TEMP%\bdbrowserskinres\baiyun.png
- %TEMP%\bdbrowserskinres\banner.png
- %TEMP%\BlueBox_<Имя вируса>_S_Setup
- %PROGRAM_FILES%\baidu\BaiduBrowser\browserconfig
- %TEMP%\setupplugins.dll
- %TEMP%\nsx3.tmp\System.dll
- 'ap#.gsie.cn':80
- '12#.#25.114.144':80
- '12###.iboluo.cc':80
- 'localhost':1036
- 'up####.u.gsie.cn':80
- ap#.gsie.cn/boxUpVer?ui#################################################################################################################
- 12###.iboluo.cc/bluebox.html?ac##################################################################################
- up####.u.gsie.cn/install/?ve###########################################################################################################################################
- DNS ASK up####.safe.my.iedun.cn
- DNS ASK st##.##ient.baidu.com
- DNS ASK ap#.gsie.cn
- DNS ASK up####.u.gsie.cn
- DNS ASK 12###.iboluo.cc
- ClassName: 'BaiduBrowserDoctor_MessageWindow' WindowName: '%APPDATA%\baidu\browser\%USERNAME%'
- ClassName: 'BaiduBrowser_MessageWindow' WindowName: '%APPDATA%\baidu\browser\%USERNAME%'
- ClassName: 'BaiduBrowser_MessageWindow' WindowName: 'BaiduBrowserMsgWnd\0'
- ClassName: 'BaiduBrowser_MessageWindow' WindowName: '(null)'
- ClassName: 'BaiduBrowserDoctor_MessageWindow' WindowName: 'BaiduBrowserMsgWnd\0'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Internet Explorer_TridentDlgFrame' WindowName: '(null)'
- ClassName: 'BaiduBrowser_MessageWindow' WindowName: '%APPDATA%/baidu/browser/%USERNAME%'
- ClassName: '#32770' WindowName: '????? ??: ????'