Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ikmtot] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\rivgih] 'Start' = '00000002'
- <SYSTEM32>\sc.exe create ikmtot type= kernel start= auto binpath= "%PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\ikmtot.bin"
- <SYSTEM32>\sc.exe create rivgih type= kernel binpath= "%PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\rivgih.bin" start= auto
- %WINDIR%\inf\aee2911
- %WINDIR%\system\cj3267.drv
- %WINDIR%\inf\jp4880.PNF
- %PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\ikmtot.bin
- %WINDIR%\msapps\ue5903.nfo
- %WINDIR%\repair\twz6152
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\az[1].php
- %TEMP%\1.tmp
- %WINDIR%\Temp\{cace1029-df48-4384-00bf-8f9f46a6253d}
- %PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\rivgih.bin
- %PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\ikmtot.bin
- %WINDIR%\Temp\{cace1029-df48-4384-00bf-8f9f46a6253d}
- %PROGRAM_FILES%\Uninstall Information\{0d0db89a-0b60-4c13-00be-6eb2bb924f8a}\rivgih.bin
- %TEMP%\1.tmp
- 'rp##.21civ.com':80
- 'localhost':1035
- rp##.21civ.com/az.php?o=###################################################
- DNS ASK www.ba##u.com
- DNS ASK rp##.21civ.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''