Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'System' = ''
- <SYSTEM32>\rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 %WINDIR%\INF\PCHealth.inf/S
- <SYSTEM32>\cscript.exe %TEMP%\1.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\2092ocrryoam[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\3[1]
- %TEMP%\1.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\freecontent[1]
- %TEMP%\1.vbs
- 'av##v.com':80
- '20####dult-2008.com':80
- 'localhost':1035
- '0b#####orpornmovie.com':80
- 20####dult-2008.com/vmovie/teen/5/1/697/3/
- av##v.com/_ioymsaxo/2092ocrryoam.exe
- 0b#####orpornmovie.com/freecontent/?id#####
- DNS ASK 20####dult-2008.com
- DNS ASK av##v.com
- DNS ASK 0b#####orpornmovie.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Error 118'