Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}] 'StubPath' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Runonce' = '<SYSTEM32>\runouce.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = ''
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\ctfmon.exe
- %CommonProgramFiles%\System\ado\readme.eml
- %CommonProgramFiles%\Microsoft Shared\Stationery\readme.eml
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\readme.eml
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\feeds\readme.eml
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\certerror\readme.eml
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\readme.eml
- %APPDATA%\Mozilla\Firefox\Profiles\przhlnon.default\readme.eml
- C:\avira antivirus\avira
- <SYSTEM32>\runouce.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\readme.eml
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\readme.eml
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\readme.eml
- <SYSTEM32>\runouce.exe
- C:\avira antivirus\avira
- 'r3###.no-ip.info':81
- 'localhost':1035
- DNS ASK r3###.no-ip.info
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''