Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '2wj7md2' = '%HOMEPATH%\2wj7md2\62781.vbs'
- '%HOMEPATH%\2wj7md2\iTunesHelp.exe'
- '%TEMP%\is-BQU4Q.tmp\hideallipsetup.tmp' /SL5="$50036,3654879,54272,%HOMEPATH%\2wj7md2\hideallipsetup.exe"
- '%HOMEPATH%\2wj7md2\BlEHU.com' PjML.XPP
- '%HOMEPATH%\2wj7md2\hideallipsetup.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %TEMP%\is-BQU4Q.tmp\hideallipsetup.tmp
- %HOMEPATH%\2wj7md2\iTunesHelp.exe
- %TEMP%\is-J71N1.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\2wj7md2\62781.vbs
- %HOMEPATH%\2wj7md2\93163.cmd
- %HOMEPATH%\2wj7md2\BlEHU.com
- %HOMEPATH%\2wj7md2\UqrVwhYsLq.XQI
- %HOMEPATH%\2wj7md2\PjML.XPP
- %HOMEPATH%\2wj7md2\hideallipsetup.exe
- %HOMEPATH%\2wj7md2\wfQJLqMB.XBO
- %HOMEPATH%\2wj7md2\wfQJLqMB.XBO
- %HOMEPATH%\2wj7md2\62781.vbs
- %HOMEPATH%\2wj7md2\93163.cmd
- %HOMEPATH%\2wj7md2\UqrVwhYsLq.XQI
- %HOMEPATH%\2wj7md2\BlEHU.com
- %HOMEPATH%\2wj7md2\PjML.XPP
- 'oc####ru.noip.me':1604
- DNS ASK oc####ru.noip.me
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'