Техническая информация
- [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE www.babaw.com'
- %PROGRAM_FILES%\SoftD\!)ЧоРВИнјюК№УГЅМіМ.exe
- %PROGRAM_FILES%\SoftD\steup.ico /Q
- %WINDIR%\regedit.exe /s kang.reg
- <SYSTEM32>\cmd.exe /c ""%TEMP%\RarSFX0\kang.bat" "
- %PROGRAM_FILES%\ВМЙ«НшЦ·µјєЅ\ToolsSafe.exe
- %TEMP%\RarSFX0\kang.reg
- %HOMEPATH%\Start Menu\Programs\ВМЙ«НшЦ·µјєЅ.lnk
- %HOMEPATH%\Desktop\ВМЙ«НшЦ·µјєЅ.lnk
- %PROGRAM_FILES%\SoftD\!)ЧоРВИнјюК№УГЅМіМ.exe
- %PROGRAM_FILES%\SoftD\steup.ico
- %TEMP%\RarSFX0\kang.bat
- %TEMP%\RarSFX0\kang.reg
- %TEMP%\RarSFX0\kang.bat
- %TEMP%\RarSFX0\kang.reg
- %PROGRAM_FILES%\SoftD\steup.ico
- %TEMP%\~DF381A.tmp
- %TEMP%\RarSFX0\kang.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''