Техническая информация
- %TEMP%\~nsu.tmp\Au_.exe _?=%TEMP%\
- %TEMP%\uninst.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://do##.##adown.com:8080/alltj.html?co########
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://do##.##adown.com:8080/alltj.html?DK####
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://do##.##adown.com:8080/alltj.html?ha########
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://do##.##adown.com:8080/alltj.html?ki######
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://do##.##adown.com:8080/alltj.html?pp########
- %TEMP%\nsf5.tmp
- %TEMP%\uninst.exe
- %TEMP%\nsp7.tmp
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsn3.tmp\InetLoad.dll
- %TEMP%\nsc2.tmp
- %TEMP%\temp.ini
- %TEMP%\nsn3.tmp\System.dll
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\nsn3.tmp\InetLoad.dll
- %TEMP%\nsn3.tmp\System.dll
- 'localhost':1047
- 'localhost':1052
- 'localhost':1053
- 'do##.#padown.com':8080
- 'localhost':1043
- 'localhost':1044
- DNS ASK do##.#padown.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''