Техническая информация
- [HKLM\Software\Classes\Inkfile\shell\open\command] '' = 'WScript.exe "%ProgramFiles%\qgifftiyd.oakpy" "%1"'
- [HKLM\Software\Classes\qcfile\shell\open\command] '' = 'WScript.exe "%ProgramFiles%\qgifftiyd.oakpy" "%1"'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://www.58lala.com/?bymf
- %ProgramFiles%\read.txt
- C:\users\public\desktop\acrobat reader dc.ink
- C:\users\public\desktop\firefox.ink
- C:\users\public\desktop\mozilla thunderbird.ink
- C:\users\public\desktop\opera.ink
- C:\users\public\desktop\steam.ink
- %HOMEPATH%\desktop\google chrome.ink
- %HOMEPATH%\desktop\telegram.ink
- C:\about blank.htm
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer (64-bit).ink
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer.ink
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\google chrome.ink
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\launch internet explorer browser.ink
- C:\about blank.htm
- DNS ASK 58##la.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''