Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'VirusRemover2008' = '%PROGRAM_FILES%\VirusRemover2008\VRM2008.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\VirusRemover2008\VirusRemover2008.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\VirusRemover2008.lnk
- %PROGRAM_FILES%\VirusRemover2008\VRM2008.exe
- %HOMEPATH%\Desktop\VirusRemover2008.lnk
- 'fl##.####virusremover2008.com':80
- '20#.#6.232.182':80
- fl##.####virusremover2008.com/?ac##############################################
- fl##.####virusremover2008.com/
- 20#.#6.232.182/
- DNS ASK fl##.####virusremover2008.com
- DNS ASK windowsupdate.microsoft.com
- ClassName: 'Button' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''