Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wennm' = '%ProgramFiles%\addendum_sb\wennmup.exe'
- '%ProgramFiles%\addendum_sb\wennmup.exe' (загружен из сети Интернет)
- '%ProgramFiles%\addendum_sb\wennmup.exe' <Полный путь к файлу>
- %ProgramFiles%\addendum_sb\wennmmgr.exe
- %ProgramFiles%\addendum_sb\wennmup.exe
- %ProgramFiles%\addendum_sb\wennmib.dll
- %TEMP%\nss2.tmp\nsRandom.dll
- %ProgramFiles%\addendum_sb\wennmim.dll
- %ProgramFiles%\addendum_sb\uninst.exe
- %HOMEPATH%\Templates\whoisk.xml
- %TEMP%\nss2.tmp\InetLoad.dll
- %TEMP%\nss2.tmp\xml.dll
- %HOMEPATH%\Templates\urlcheck.xml
- %TEMP%\nss2.tmp\version.dll
- %TEMP%\nss2.tmp\nsRandom.dll
- %TEMP%\nss2.tmp\version.dll
- %TEMP%\nss2.tmp\xml.dll
- %HOMEPATH%\Templates\whoisk.xml
- %HOMEPATH%\Templates\urlcheck.xml
- %TEMP%\nss2.tmp\InetLoad.dll
- 'ap##.#smon.co.kr':80
- http://ap##.#smon.co.kr/filewennm/v2/wennmib.dll
- http://ap##.#smon.co.kr/filewennm/v2/wennmmgr.exe
- http://ap##.#smon.co.kr/app/inst_ok.asp?ui################################################
- http://ap##.#smon.co.kr/filewennm/v2/wennmim.dll
- http://ap##.#smon.co.kr/app/urlcheck.asp?ic######
- http://ap##.#smon.co.kr/app/ipcheck.asp
- http://ap##.#smon.co.kr/filewennm/v2/wennmup.exe
- http://ap##.#smon.co.kr/filewennm/v2/uninst.exe
- DNS ASK ap##.#smon.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''