Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ToolbarRestore' = '%PROGRAM_FILES%\ILikeClick\ToolbarRestore.exe'
- %PROGRAM_FILES%\ILikeClick\install.exe Y;<Полный путь к вирусу>;20367704
- %PROGRAM_FILES%\ILikeClick\akmall.ico
- %PROGRAM_FILES%\ILikeClick\emart.ico
- %PROGRAM_FILES%\ILikeClick\А§ёЮЗБ.ico
- %PROGRAM_FILES%\ILikeClick\ЗцґлИЁјоЗО.ico
- %TEMP%\nsg2.tmp\System.dll
- %PROGRAM_FILES%\ILikeClick\IlikeClick.ini
- %PROGRAM_FILES%\ILikeClick\GSИЁјоЗО.ico
- %PROGRAM_FILES%\ILikeClick\halfclub.ico
- %PROGRAM_FILES%\ILikeClick\ЅЕјј°иёф.ico
- %PROGRAM_FILES%\ILikeClick\gmarket_mone.ico
- %PROGRAM_FILES%\ILikeClick\11market.ico
- %PROGRAM_FILES%\ILikeClick\install.exe
- %PROGRAM_FILES%\ILikeClick\uninstall.exe
- %PROGRAM_FILES%\ILikeClick\Update.exe
- %PROGRAM_FILES%\ILikeClick\·ФµҐИЁјоЗО.ico
- %PROGRAM_FILES%\ILikeClick\Auction.ICO
- %PROGRAM_FILES%\ILikeClick\ToolbarRestore.exe
- %TEMP%\nsg2.tmp\System.dll
- 'li#####.ilikeclick.com':80
- DNS ASK li#####.ilikeclick.com