Код:
Ключи реестра: 13
PUP.Optional.ToolBar.WA, HKLM\SOFTWARE\CLASSES\CLSID\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A}, , [df66f5a1acdec5713dfbd2bda65d946c],
PUP.Optional.ToolBar.WA, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A}, , [9ea73660e3a7eb4b1721b5da54af3dc3],
PUP.Optional.ToolBar.WA, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A}, , [b19499fde1a9e056fd3b2d629271b24e],
PUP.Optional.ToolBar.WA, HKLM\SOFTWARE\CLASSES\nsWebAlta.WebAltaSearchBar, , [cc79fa9ce7a3de584fe9e9a6bd466799],
PUP.Optional.FunMoods.A, HKLM\SOFTWARE\INSTALLCORE\funmoods, , [43021e78bbcf3afc4f69fd22e4215ea2],
PUP.Optional.VoPackage.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPackage, , [a89d2472345668ce8b97bbb11aeb6c94],
PUP.Optional.RegCleanerPro.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1000\SOFTWARE\SYSTWEAK\RegClean Pro, , [063f5f371377c1754cc271d314f1837d],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\DSiteProducts, , [76cf7620107a51e5347284e19d689a66],
PUP.FunMoods, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\Funmoods, , [c3824f47c0ca0f279ef16fc1ac5851af],
PUP.Optional.PassShow.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\APPDATALOW\SOFTWARE\PassShow, , [172e41558ffb85b19a0db73fe1226d93],
PUP.FunMoods, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\INSTALLCORE\funmoods, , [ca7b10868307b482b2de74bc828255ab],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\INSTALLCORE, , [380d2f676f1b78beb6c3de60897cbb45],
PUP.Optional.RegCleanerPro.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\SYSTWEAK\RegClean Pro, , [df66b0e64347e25425e9162ea26318e8],
Параметры реестра: 2
PUP.Optional.VOPackage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPACKAGE|UninstallString, "C:\Users\????N????? ????N??µN?????\AppData\Roaming\VOPackage\uninstall.exe", , [cc79afe7a5e5082e3842a75eaf5520e0]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\INSTALLCORE|tb, 1P1O1N1R1G1M1J, , [380d2f676f1b78beb6c3de60897cbb45]
Данные реестра: 2
Hijack.StartPage, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://webalta.ru/search, Хорошо: (http://www.google.com/), Плохо: (http://webalta.ru/search),,[8db86a2c91f92c0a63a6d6497f87a858]
Hijack.SearchPage, HKU\S-1-5-21-1131328099-337311330-2945725469-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://webalta.ru/search, Хорошо: (http://www.Google.com/), Плохо: (http://webalta.ru/search),,[b98c405627632610dae161bc9d69926e]
Папки: 8
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DSite\UpdateProc, , [172e088ec6c4f24418be6b5251b21fe1],
PUP.Optional.VOPackage.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\VOPackage, , [24217422cebc51e59f53f1de56ad2ed2],
PUP.Optional.VOPackage.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage, , [fc49e2b4e0aacf676c8718b760a38e72],
PUP.Optional.ToolBar.WA, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webalta Toolbar, , [e263ebab51394cea222f6a66e122639d],
Файлы: 42
Trojan.Agent, C:\Users\????N????? ????N??µN?????\Thumbsdb.bat, , [63e270267f0bbb7ba8def9fb847fe719],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\config.dat, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\gup_dt.dat, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\info.dat, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\MESSAGE.txt, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\STTL.DAT, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.FunMoods.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Funmoods\UpdateProc\TTL.DAT, , [b68fdbbbe0aaa29469f530facc38c13f],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\MESSAGE.txt, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\ExcludeList.rcp, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\log_05-30-2014.log, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\MESSAGE.txt, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\russian_rcp_ru.dat, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.RegCleanerPro.A, C:\Users\USER\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\TempHLList.rcp, , [370ea9eda3e794a2764f7e2948bbc040],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc\config.dat, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc\info.dat, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc\MESSAGE.txt, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc\STTL.DAT, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DigitalSites\UpdateProc\TTL.DAT, , [6dd8dcba3852bf7709cb566745be837d],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DSite\UpdateProc\info.dat, , [172e088ec6c4f24418be6b5251b21fe1],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DSite\UpdateProc\MESSAGE.txt, , [172e088ec6c4f24418be6b5251b21fe1],
PUP.Optional.Updater.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\DSite\UpdateProc\prod.dat, , [172e088ec6c4f24418be6b5251b21fe1],
PUP.Optional.VOPackage.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\VOPackage\MESSAGE.txt, , [24217422cebc51e59f53f1de56ad2ed2],
PUP.Optional.VOPackage.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\Configure.lnk, , [fc49e2b4e0aacf676c8718b760a38e72],
PUP.Optional.VOPackage.A, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\MESSAGE.txt, , [fc49e2b4e0aacf676c8718b760a38e72],
PUP.Optional.ToolBar.WA, C:\Users\????N????? ????N??µN?????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webalta Toolbar\MESSAGE.txt, , [e263ebab51394cea222f6a66e122639d],