Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\desktops.lnk
- '%TEMP%\RarSFX0\irn.exe'
- '%TEMP%\is-CSN5S.tmp\irn.tmp' /SL5="$2010A,706656,54272,%TEMP%\RarSFX0\irn.exe"
- '%TEMP%\is-GDO6S.tmp\irn.tmp' /SL5="$20124,57124,54272,%TEMP%\is-CSN5S.tmp\irn.tmp" /SL5="$2010A,706656,54272,%TEMP%\RarSFX0\irn.exe"
- '%TEMP%\RarSFX0\app.exe' /S
- 'C:\Desktops Alert\desktops.exe'
- '%TEMP%\RarSFX0\Bnd_160_82_2014128_1857.exe'
- C:\Desktops Alert\Interop.IWshRuntimeLibrary.dll
- C:\Desktops Alert\Interop.Shell32.dll
- C:\Desktops Alert\uninstall\uninstall.exe
- C:\Desktops Alert\desktops.exe
- %TEMP%\is-J75FM.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-J75FM.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-CSN5S.tmp\irn.tmp
- %TEMP%\is-GDO6S.tmp\irn.tmp
- %TEMP%\RarSFX0\irn.exe
- %TEMP%\RarSFX0\hm.exe
- %TEMP%\RarSFX0\app.exe
- %TEMP%\RarSFX0\Bnd_160_82_2014128_1857.exe
- C:\Desktops Alert\uninstall\silmek.bmp
- C:\Desktops Alert\uninstall\silmek.txt
- %TEMP%\RarSFX0\git.url
- C:\Desktops Alert\uninstall\privacy.txt
- 'mz.##.trtromg.com':80
- 'ip##fo.io':80
- ip##fo.io/country
- mz.##.trtromg.com/s2.php
- mz.##.trtromg.com/r2.php
- DNS ASK mz.##.trtromg.com
- DNS ASK ip##fo.io
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''