Техническая информация
- %APPDATA%\GoogleNMore\InstValid.exe -val:Tomtomax Radars Pack premium du 25 11 2011
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.Yo##idz.com/ThankYou.aspx?v=################ Radars Pack premium du 25 11 2011
- <SYSTEM32>\regsvr32.exe "%APPDATA%\GoogleNMore\3.GoogleNMore.dll"
- %APPDATA%\GoogleNMore\FFExt\chrome\content\googlenmore.js
- %APPDATA%\GoogleNMore\FFExt\chrome\content\googlenmore.xul
- %APPDATA%\GoogleNMore\FFExt\chrome.manifest
- %APPDATA%\GoogleNMore\FFExt\install.rdf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\VerInfo11[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\ThankYou[1].aspx
- %APPDATA%\GoogleNMore\GNMLog.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\SrvConfig11[1].aspx
- %APPDATA%\GoogleNMore\GoogleNMoreLicense32.txt
- %APPDATA%\GoogleNMore\GoogleNMore.ini
- %APPDATA%\GoogleNMore\MFC42U.DLL
- %APPDATA%\GoogleNMore\Uninstall.bat
- %APPDATA%\GoogleNMore\GoogleNMoreXPCOM.dll
- %APPDATA%\GoogleNMore\IGoogleNMoreXPCOM.xpt
- %APPDATA%\GoogleNMore\3.GoogleNMore.dll
- %APPDATA%\GoogleNMore\InstValid.exe
- 'www.yo##idz.com':80
- 'localhost':1036
- www.yo##idz.com/ThankYou.aspx?v=################################################################
- www.yo##idz.com/download11/VerInfo11.txt?My#########
- www.yo##idz.com/SrvConfig11.aspx?My#########
- DNS ASK www.yo##idz.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''