Техническая информация
- [<HKLM>\SOFTWARE\Classes\Software\Microsoft\Windows\CurrentVersion\Run] 'Adobe flash Updater' = '%APPDATA%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Adobe flash Updater' = '%APPDATA%\svchost.exe'
- '%PROGRAM_FILES%\svhost\instal.exe'
- '%APPDATA%\svchost.exe' Soft live
- '%APPDATA%\wap.exe' Adobe flash Updater
- '%PROGRAM_FILES%\svhost\instal.exe' (загружен из сети Интернет)
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- C:\Uninstall.exe
- %APPDATA%\wapUpdates4.dat
- %APPDATA%\wap2settings.dat
- %PROGRAM_FILES%\svhost\instal.exe
- C:\Uninstall.ini
- %APPDATA%\Tutorial.pdf
- %APPDATA%\svchost.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %APPDATA%\telelist.ini
- %APPDATA%\tools\teleconvert.exe
- %APPDATA%\wap.exe
- <SYSTEM32>\d3d9caps.dat
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- <SYSTEM32>\d3d9caps.tmp в <SYSTEM32>\d3d9caps.dat
- 'xz##ow.ru':80
- 'wp#d':80
- xz##ow.ru/niga.exe
- wp#d/wpad.dat
- DNS ASK xz##ow.ru
- DNS ASK wp#d
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '' WindowName: 'World of Warcraft'
- ClassName: 'Shell_TrayWnd' WindowName: ''