Техническая информация
- [<HKLM>\SOFTWARE\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\Shell\Open\Command] '' = '%PROGRAM_FILES%\Internet Explorer\SIGNUP\iexplore.exe %1 h%t%t%p:%//%w%w%w.h%uh%u123.%c%o%m'
- скрытых файлов
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.wu##6.com/?1
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.ak##.com/?1
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.xi##wo.com/index1.html
- %HOMEPATH%\Desktop\°Щ¶И.ink
- %HOMEPATH%\Desktop\360°ІИ«НшЦ·µјєЅ.ink
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\aku6[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index1[1].html
- %HOMEPATH%\Desktop\МФ±¦Нш.ink
- %PROGRAM_FILES%\Internet Explorer\SIGNUP\iexplore.exe
- %HOMEPATH%\Desktop\ОТµДЙПНшЦчТі.ink
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Exlporer дЇААЖч.ink
- 'www.xi##wo.com':80
- 'www.ak##.com':80
- 'localhost':1037
- 'localhost':1036
- www.ak##.com/?1
- www.xi##wo.com/index1.html
- DNS ASK www.ak##.com
- DNS ASK www.xi##wo.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''