Техническая информация
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '%APPDATA%\cLLL.exe' "%APPDATA%\GBSaN.au3"
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- [<HKCU>\Software\IMVU\username]
- %APPDATA%\GBSaN.au3
- %ALLUSERSPROFILE%\Application Data\CRNJEUFU_10_13_6_51_1.jpg
- %APPDATA%\cLLL.exe
- %TEMP%\aut1.tmp
- %TEMP%\pjbigdl
- %TEMP%\pjbigdl
- %TEMP%\aut1.tmp
- 'www.tw####sixjune.biz':80
- 'wp#d':80
- http://www.tw####sixjune.biz/davidk27sept=27oct/post.php?ty##########################################################
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK www.tw####sixjune.biz
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''