Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{02496EBD-8455-48db-B3C7-5DAC97D9F5A7}] 'Exec' = 'http://www.baidu.com'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BIE' = 'RUNDLL32.EXE %PROGRAM_FILES%\baidu\iexp\BDSrHook.dll,Rundll32'
- '<SYSTEM32>\rundll32.exe' %PROGRAM_FILES%\baidu\iexp\BDSrHook.dll,Rundll32
- %HOMEPATH%\Favorites\БґЅУ\°Щ¶ИЎЄЎЄИ«ЗтЧоґуЦРОДЛСЛчТэЗж.url
- %PROGRAM_FILES%\baidu\bar\BaiduBar.dll
- %PROGRAM_FILES%\baidu\iexp\BDSrHook.dll
- %HOMEPATH%\Favorites\°Щ¶ИЎЄЎЄИ«ЗтЧоґуЦРОДЛСЛчТэЗж.url
- %PROGRAM_FILES%\baidubar\BaiduBar.dll
- %PROGRAM_FILES%\baidubar\baidubar.dat
- %PROGRAM_FILES%\baidubar\BDSrHook.dll
- %PROGRAM_FILES%\baidubar\BDSrHook.dll
- %PROGRAM_FILES%\baidubar\BaiduBar.dll