Техническая информация
- [<HKLM>\software\microsoft\windows\currentversion\run] 'NETUTILS' = '%WINDIR%\8D0EvNoF9SlD.exe'
- %HOMEPATH%\start menu\programs\startup\idwn5i89.exe
- %ALLUSERSPROFILE%\start menu\programs\startup\idwn5i89.exegswpyh5lwb.exe
- <SYSTEM32>\shutdown.exe
- %APPDATA%\icqm\icqsetup.exe
- %TEMP%\downloader.exe
- %HOMEPATH%\my documents\icq_rfrset.exe
- %ProgramFiles%\adobe\reader 10.0\reader\acrord32.exe
- %ProgramFiles%\adobe\reader 10.0\reader\acrord32info.exe
- %ProgramFiles%\aim6\aim6.exe
- %ProgramFiles%\aimpro\aimpro.exe
- %ProgramFiles%\autodown\autodown.exe
- %ProgramFiles%\icq\icq.exe
- %ProgramFiles%\icqlite\icqlite.exe
- %ProgramFiles%\navwnt\navwnt.exe
- %ProgramFiles%\pidgin\gtk\bin\gspawn-win32-helper-console.exe
- %ProgramFiles%\pidgin\gtk\bin\gspawn-win32-helper.exe
- %ProgramFiles%\usdownloader\usdownloader.exe
- %ProgramFiles%\winrar\winrar.exe
- <SYSTEM32>\shutdown.exe
- Cредство проверки системных файлов (SFC)
- %WINDIR%\8d0evnof9sld.exe
- %TEMP%\~rgeffere.tmp
- <SYSTEM32>\shutdown.exe.new
- <SYSTEM32>\dllcache\shutdown.exe.new
- %WINDIR%\8d0evnof9sld.exe
- %HOMEPATH%\start menu\programs\startup\idwn5i89.exe
- %ALLUSERSPROFILE%\start menu\programs\startup\idwn5i89.exegswpyh5lwb.exe
- %TEMP%\~rgeffere.tmp
- %TEMP%\~rgeffere.tmp
- '12#.#7.9.247':6667