Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'co71168J41796' = '%HOMEPATH%\tj66962W30830\winIogon.exe'
- '%HOMEPATH%\tj66962W30830\winIogon.exe'
- '%HOMEPATH%\cc.exe'
- '%HOMEPATH%\rl57904O29554\hv46036C15878.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %HOMEPATH%\aa.jpg
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\Recent\aa.lnk
- %HOMEPATH%\tj66962W30830\CI.TKZ
- %HOMEPATH%\Recent\%USERNAME%.lnk
- %HOMEPATH%\zc87192I98255.TF8
- %TEMP%\aut3.tmp
- %HOMEPATH%\tj66962W30830\winIogon.exe
- %TEMP%\aut1.tmp
- %HOMEPATH%\rl57904O29554\hv46036C15878.exe
- %HOMEPATH%\cc.exe
- %HOMEPATH%\aa.jpg
- %TEMP%\aut2.tmp
- %HOMEPATH%\zc87192I98255.TF8
- %HOMEPATH%\aa.jpg
- %HOMEPATH%\cc.exe
- %TEMP%\aut3.tmp
- %HOMEPATH%\zc87192I98255.TF8
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'wi#####7lic.no-ip.biz':4431
- DNS ASK wi#####7lic.no-ip.biz
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'