Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'New2Clean' = '%ProgramFiles%\New2Clean\New2CleanLaunch.exe'
- '' (загружен из сети Интернет)
- %ProgramFiles%\New2Clean\uninst.exe
- %HOMEPATH%\Start Menu\Programs\New2Clean\ИЁЖдАМБц.lnk
- %ProgramFiles%\New2Clean\New2Clean.url
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\inst[1].php
- %ProgramFiles%\New2Clean\123.bat
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\list[1].html
- %APPDATA%\MZђ
- %HOMEPATH%\Start Menu\Programs\New2Clean\New2Clean.lnk
- %ProgramFiles%\New2Clean\New2CleanUp.exe
- %TEMP%\nsv2.tmp
- %ProgramFiles%\New2Clean\New2CleanLaunch.exe
- %ProgramFiles%\New2Clean\data\dt.cab
- %ProgramFiles%\New2Clean\ovsavn.exe
- %ProgramFiles%\New2Clean\New2Clean.exe
- 'we##ide.kr':80
- 'ne###ean.pe.kr':80
- http://ne###ean.pe.kr/app/update/list.html
- http://we##ide.kr/link/rand/runexe7.php
- http://ne###ean.pe.kr/count/inst.php?uc####################################
- DNS ASK we##ide.kr
- DNS ASK ne###ean.pe.kr
- ClassName: 'MS_WINHELP' WindowName: ''
- '%ProgramFiles%\New2Clean\New2CleanUp.exe'
- '%APPDATA%\MZђ'
- '%ProgramFiles%\New2Clean\ovsavn.exe'
- '%ProgramFiles%\New2Clean\New2Clean.exe' /install
- '%ProgramFiles%\New2Clean\New2CleanLaunch.exe'
- '%WINDIR%\sleep.exe' 5
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\New2Clean\123.bat" "