Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ucn' = '<SYSTEM32>\ucn.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\ucn.exe' = '<SYSTEM32>\ucn.exe:*:Enabled:DeskUpdata'
- %HOMEPATH%\Favorites\G-ё¶ДП.url
- %HOMEPATH%\Favorites\їБјЗ.url
- %TEMP%\nsn2.tmp\NSISdl.dll
- %PROGRAM_FILES%\urlclean\uninst.exe
- %HOMEPATH%\Favorites\install_log.php
- <SYSTEM32>\ucn.exe
- %PROGRAM_FILES%\urlclean\urlclean.dll
- <SYSTEM32>\uclean.ucn
- <SYSTEM32>\auction.ico
- <SYSTEM32>\gmarket.ico
- %TEMP%\nsn2.tmp\NSISdl.dll
- %HOMEPATH%\Favorites\install_log.php
- 'ur###ean.com':80
- ur###ean.com/log/install_log.php
- DNS ASK ur###ean.com