Техническая информация
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://tc.go4321.com/
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://www.38522.com/baohanye.htm
- %HOMEPATH%\favorites\¾«²êð¡óîï·.url
- %HOMEPATH%\favorites\ñôçéð¡ëµ.url
- %HOMEPATH%\favorites\ГГёГ¶В·ВґГіГЁВ«.url
- %HOMEPATH%\desktop\´´òµö×êºãïîä¿.url
- %HOMEPATH%\desktop\°ëøôé«ГВј.url
- %HOMEPATH%\desktop\ãà å®êóæµ.url
- %HOMEPATH%\desktop\ãà å®à öô°.url
- %APPDATA%\microsoft\windows\start menu\internet explorer.lnk
- %WINDIR%\syswow64\tbhdz.ico
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
- 'do####ad.youbak.com':80
- http://do####ad.youbak.com/msn/software/partner/PARTNER2093.exe
- DNS ASK do####ad.youbak.com
- DNS ASK 38##2.com
- DNS ASK tc.##4321.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://www.38522.com/baohanye.htm' (со скрытым окном)