Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnZoneCrossing' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- %HOMEPATH%\Desktop\System Check.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
- %HOMEPATH%\Start Menu\Programs\System Check\Uninstall System Check.lnk
- %ALLUSERSPROFILE%\Application Data\G92wTxQFy
- %HOMEPATH%\Start Menu\Programs\System Check\System Check.lnk
- из <Полный путь к файлу> в %ALLUSERSPROFILE%\Application Data\G92wTxQFy.exe
- 'me###eigol.com':80
- 'li###otaltv.com':80
- 'ma####ngelog.com':80
- 'sk###ljus.com':80
- 'wa###lber.com':80
- 'mm##and.com':80
- http://li###otaltv.com/britix/a
- http://me###eigol.com/britix/ar
- http://me###eigol.com/britix/a
- http://ma####ngelog.com/britix/ar
- http://ma####ngelog.com/britix/a
- http://li###otaltv.com/britix/ar
- http://wa###lber.com/britix/ar
- http://sk###ljus.com/britix/ar
- http://wa###lber.com/up.php?0Q##########################################################################
- http://sk###ljus.com/britix/a
- http://wa###lber.com/britix/a
- http://mm##and.com/britix/ar
- http://mm##and.com/britix/a
- DNS ASK me###eigol.com
- DNS ASK li###otaltv.com
- DNS ASK ma####ngelog.com
- DNS ASK sk###ljus.com
- DNS ASK wa###lber.com
- DNS ASK mm##and.com