Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5UR3WO37-QFNP-EMV6-555N-W1Y20I81JBHC}] 'StubPath' = '%ProgramFiles%\ReaderX\AdobeReaderX.exe Restart'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5UR3WO37-QFNP-EMV6-555N-W1Y20I81JBHC}] 'StubPath' = '%ProgramFiles%\ReaderX\AdobeReaderX.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Readeer' = '%ProgramFiles%\ReaderX\AdobeReaderX.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Readeer' = '%ProgramFiles%\ReaderX\AdobeReaderX.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\AdobeReaderX.exe
- '%ProgramFiles%\ReaderX\AdobeReaderX.exe'
- %WINDIR%\Explorer.EXE
- %TEMP%\%USERNAME%7
- %TEMP%\%USERNAME%8
- %APPDATA%\88E6680F\ak.tmp
- %ProgramFiles%\ReaderX\AdobeReaderX.exe
- %TEMP%\%USERNAME%2.txt
- %TEMP%\%USERNAME%7
- %TEMP%\%USERNAME%8
- %TEMP%\%USERNAME%2.txt
- %TEMP%\%USERNAME%7
- %TEMP%\%USERNAME%8
- 'up####e.myvnc.com':7777
- 'al#####e.myq-see.com':7777
- DNS ASK up####e.myvnc.com
- DNS ASK al#####e.myq-see.com
- ClassName: 'Shell_TrayWnd' WindowName: ''