Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'DirectPlay8WSock' = '{8d7c0b06-5739-4de4-8879-c9dc030bcb2d}'
- %TEMP%\is-V6HQK.tmp\sd-card-data-restore-software-2.0.tmp /SL5="$300DA,1137680,54272,%TEMP%\sd-card-data-restore-software-2.0.exe"
- %TEMP%\sd-card-data-restore-software-2.0.exe
- <SYSTEM32>\regsvr32.exe /s "%TEMP%\windll.dll"
- %TEMP%\sd-card-data-restore-software-2.0.log
- %TEMP%\is-CV3E7.tmp\isxdl.dll
- %CommonProgramFiles%\DirectPlay8\DirectPlay8WSock.dll
- %TEMP%\windll.dll
- %TEMP%\is-CV3E7.tmp\_isetup\_shfoldr.dll
- %TEMP%\nsa2.tmp\NSISdl.dll
- %TEMP%\sd-card-data-restore-software-2.0.exe
- %TEMP%\is-CV3E7.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-V6HQK.tmp\sd-card-data-restore-software-2.0.tmp
- %TEMP%\nsa2.tmp\NSISdl.dll
- %TEMP%\windll.dll
- 'cu####tversion.biz':80
- cu####tversion.biz/windows/version.php?ve###########################################
- DNS ASK cu####tversion.biz
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MozillaUIWindowClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''