Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '"%PROGRAM_FILES%\Systim\Systim.exe" -s -t 600'
- '%PROGRAM_FILES%\Systim\systim.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://m.###t.com?p1#
- '<SYSTEM32>\cmd.exe' /c ""%PROGRAM_FILES%\Systim\1.bat" "
- %HOMEPATH%\Favorites\5diq═°╓╖╡╝║╜.url
- %PROGRAM_FILES%\Systim\systim.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\m.55et[1]
- %PROGRAM_FILES%\Systim\±Шїґ.txt
- %PROGRAM_FILES%\Systim\1.bat
- %TEMP%\$inst\4.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\5.tmp
- %TEMP%\$inst\4.tmp
- %TEMP%\$inst\5.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- 'm.##et.com':80
- 'localhost':1037
- m.##et.com/?p1#
- DNS ASK m.##et.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''