Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xizldugi' = '"<LS_APPDATA>\xizldugi.exe" xizldugi'
- <LS_APPDATA>\xizldugi.exe INSTALL:|1485||172800|1
- %WINDIR%\Explorer.EXE
- firefox.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Original-Solitaire\uninstall.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Original-Solitaire\Original-Solitaire.lnk
- %PROGRAM_FILES%\Original-Solitaire\data\translation_file_original_solitaire.xml
- %ALLUSERSPROFILE%\Desktop\Original-Solitaire.lnk
- %TEMP%\website_AC_RunActiveContent_js.dat
- %TEMP%\Original-Solitaire_exe.dat
- %TEMP%\nsk3.tmp\NSISdl.dll
- %TEMP%\nsk3.tmp\modern-wizard.bmp
- %TEMP%\nsk3.tmp\ioSpecial.ini
- %TEMP%\nsn2.tmp
- %TEMP%\nsk3.tmp\modern-header.bmp
- <LS_APPDATA>\xizldugi.dat
- %WINDIR%\Temp\msksetup.log
- <LS_APPDATA>\xizldugi.exe
- 'do######.original-solitaire.com':80
- do######.original-solitaire.com/Solitaire_download.php?fi#############################
- do######.original-solitaire.com/Solitaire_download.php?fi#####################################
- do######.original-solitaire.com/Solitaire_download.php?fi#########################
- DNS ASK do######.Original-Solitaire.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: '#32770' WindowName: 'Original-Solitaire'
- ClassName: 'Shell_TrayWnd' WindowName: ''