Техническая информация
- '%TEMP%\RarSFX1\z81.exe'
- '%TEMP%\RarSFX0\wanwan2009_10126.exe'
- '%TEMP%\is-TDR20.tmp\wanwan2009_10126.tmp' /SL5="$20106,1545083,52224,%TEMP%\RarSFX0\wanwan2009_10126.exe"
- '%TEMP%\RarSFX0\pp0075.exe'
- '%TEMP%\RarSFX0\1.exe'
- '%TEMP%\RarSFX1\pp0075.exe'
- %PROGRAM_FILES%\Internet Explorer\Internet Explorer.url
- %PROGRAM_FILES%\Internet Explorer\del.bat
- <SYSTEM32>\67-105-7163
- %WINDIR%\3.tmp
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %TEMP%\is-67L4D.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-67L4D.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Start Menu\Internet Explorer.lnk
- %TEMP%\is-TDR20.tmp\wanwan2009_10126.tmp
- %TEMP%\nsv2.tmp
- %HOMEPATH%\Favorites\ЙПНшµјєЅ.url
- %TEMP%\RarSFX0\wanwan2009_10126.exe
- %TEMP%\RarSFX0\pp0075.exe
- %HOMEPATH%\Favorites\µҐ»ъУОП·ПВФШ.url
- %TEMP%\RarSFX1\z81.exe
- %TEMP%\RarSFX1\pp0075.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Explorer дЇААЖч.lnk
- %TEMP%\RarSFX0\1.exe
- %TEMP%\RarSFX1\z81.exe
- %TEMP%\RarSFX0\1.exe
- %WINDIR%\3.tmp
- %TEMP%\RarSFX1\pp0075.exe
- '88#.#43call.cn':80
- 88#.#43call.cn/pw.ini
- DNS ASK 88#.#43call.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'