Техническая информация
- [<HKLM>\SOFTWARE\Classes\vtxfile\Shell\open\command] '' = '%ProgramFiles%\Internet Explorer\minftnet.exe %1'
- %TEMP%\RarSFX0\6659f8b0ce5c49c9b657b3a5064f21d8.exe
- %ProgramFiles%\Internet Explorer\minftnet.exe
- %ProgramFiles%\Internet Explorer\minftnet.ini
- %TEMP%\RarSFX0\6659f8b0ce5c49c9b657b3a5064f21d8.exe
- 'localhost':1037
- 'cv####ivation.com':80
- http://www.cv####ivation.com/validInstall-conv-coll.php via cv####ivation.com
- DNS ASK www.cv####ivation.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: 'EoEngine'
- ClassName: 'TformTeaTimer' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%TEMP%\RarSFX0\6659f8b0ce5c49c9b657b3a5064f21d8.exe'
- '<SYSTEM32>\rundll32.exe' url.dll,FileProtocolHandler http://www.cv####ivation.com/validInstall-conv-coll.php
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome