Техническая информация
- [<HKLM>\Software\Classes\vtxfile\Shell\open\command] '' = '%ProgramFiles(x86)%\Internet Explorer\minftnet.exe %1'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://www.co#######n-collective-pro.com/consultation-directe
- %ProgramFiles(x86)%\internet explorer\minftnet.exe
- %ProgramFiles(x86)%\internet explorer\minftnet.ini
- %TEMP%\d9cb.tmp
- 'co#######n-collective-pro.com':80
- http://www.co#######n-collective-pro.com/consultation-directe
- DNS ASK co#######n-collective-pro.com
- ClassName: '' WindowName: 'EoEngine'
- ClassName: 'TformTeaTimer' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\D9CB.tmp,_EntryPoint {468d9dc0-bdad-4d0c-99d7-f633e959fa45}' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\D9CB.tmp,_EntryPoint {468d9dc0-bdad-4d0c-99d7-f633e959fa45}
- '<SYSTEM32>\rundll32.exe' %TEMP%\D9CB.tmp,_EntryPoint {468d9dc0-bdad-4d0c-99d7-f633e959fa45}