Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] '{D56A1203-1452-EBA1-7294-EE3377770000}' = 'Interlinking Memory Support'
- <SYSTEM32>\regsvr32.exe /s <SYSTEM32>\popup_bl.dll
- <SYSTEM32>\regsvr32.exe /s <SYSTEM32>\searchdll.dll
- <SYSTEM32>\rundll32.exe <SYSTEM32>\param32.dll,load
- <SYSTEM32>\!!! CANADIAN PHARMACY FOR THE LOWEST PRICES !!!.ico
- <SYSTEM32>\popup_bl.dll
- <SYSTEM32>\!!! LEGAL SOFTWARE SALE - SAVE HUNDREDS OF DOLLARS !!!.ico
- %TEMP%\sysldr32.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\FlashSample[1].exe
- <SYSTEM32>\searchdll.dll
- <SYSTEM32>\param32.dll
- %HOMEPATH%\Desktop\!!! CANADIAN PHARMACY FOR THE LOWEST PRICES !!!.url
- <SYSTEM32>\guninst.exe
- %HOMEPATH%\Desktop\!!! LEGAL SOFTWARE SALE - SAVE HUNDREDS OF DOLLARS !!!.url
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\FlashSample[1].exe
- 'ca###achine.com':80
- 'www.on###yoffer.biz':80
- ca###achine.com/FlashSample.exe
- www.on###yoffer.biz/system/admin.php
- DNS ASK ca###achine.com
- DNS ASK www.on###yoffer.biz
- ClassName: 'Shell_TrayWnd' WindowName: ''