Техническая информация
- [<HKLM>\SOFTWARE\Classes\lnkfile\shell\open\command] '' = '"%PROGRAM_FILES%\TXOC\TXOC.exe" "%1"'
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- %WINDIR%\regedit.exe /s "%TEMP%\209LE.reg"
- <SYSTEM32>\wscript.exe "%TEMP%\R00PT.vbs"
- %TEMP%\209LE.reg
- %TEMP%\R00PT.vbs
- %PROGRAM_FILES%\TTPlayer\Config.ini
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- <SYSTEM32>\Factory.dll
- %PROGRAM_FILES%\TXOC\TXOC.exe
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- 'bb#.##aicache.com':8081
- 'aa#.##aicache.com':8081
- 'ip#.##aicache.com':8081
- DNS ASK bb#.##aicache.com
- DNS ASK aa#.##aicache.com
- DNS ASK ip#.##aicache.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''