Техническая информация
- [HKCU\Software\Headlight\GetRight\]
- [HKLM\SOFTWARE\FileZilla Client]
- [HKLM\SOFTWARE\Wow6432Node\FileZilla Client]
- [HKCU\SOFTWARE\FileZilla Client]
- [HKCU\Software\RIT\The Bat!]
- [HKLM\Software\FlashFXP]
- [HKLM\Software\Wow6432Node\FlashFXP]
- [HKCU\Software\Headlight\GetRight]
- [HKCU\Software\IMVU]
- [HKCU\Software\mIRC]
- %APPDATA%\mozilla\firefox\profiles.ini
- %APPDATA%\thunderbird\profiles.ini
- %TEMP%\rarsfx0\ccleaner.ini
- %TEMP%\rarsfx0\ccleaner.exe
- %TEMP%\rarsfx0\branding.dll
- %TEMP%\rarsfx0\ccleaner.dat
- 'nc#.#vast.com':80
- http://nc#.#vast.com/ncc.txt
- DNS ASK nc#.#vast.com
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\ccleaner.exe'