Техническая информация
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://do##.##adown.com:8080/alltj.html?uu###
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://do##.##adown.com:8080/alltj.html?pp####
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'CurrentLevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'CurrentLevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'CurrentLevel' = '00000000'
- %TEMP%\Temporary Internet Files\Content.IE5\2NUVUZOF\desktop.ini
- %TEMP%\Temporary Internet Files\Content.IE5\PQ4NER6V\desktop.ini
- %TEMP%\uninst.exe
- %TEMP%\nsl3.tmp\System.dll
- %TEMP%\Temporary Internet Files\Content.IE5\ERD9YNO2\desktop.ini
- %TEMP%\nsl3.tmp\InetLoad.dll
- %TEMP%\nsj2.tmp
- %TEMP%\Temporary Internet Files\Content.IE5\B5RG3J3R\desktop.ini
- %TEMP%\Temporary Internet Files\Content.IE5\PQ4NER6V\desktop.ini
- %TEMP%\Temporary Internet Files\Content.IE5\2NUVUZOF\desktop.ini
- %TEMP%\Temporary Internet Files\Content.IE5\B5RG3J3R\desktop.ini
- %TEMP%\Temporary Internet Files\Content.IE5\ERD9YNO2\desktop.ini
- %TEMP%\nsl3.tmp\System.dll
- %TEMP%\nsl3.tmp\InetLoad.dll
- '60.##3.8.118':8080
- 'do##.#padown.com':8080
- DNS ASK do##.#padown.com
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''