Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Полный путь к вирусу>' = '<Полный путь к вирусу>:*:Enabled:InstallCore™'
- %TEMP%\0001BA04.log
- %TEMP%\0001BB6B.log
- %TEMP%\0001B3E9.log
- %TEMP%\ish32328544\blank.gif
- %TEMP%\ish32328544\style.css
- %TEMP%\0001CEC4.log
- %TEMP%\is233770471\1674717208.cfg
- %TEMP%\ish32328544\bootstrap_47851.html
- %TEMP%\ICReinstall\<Имя вируса>.exe
- %HOMEPATH%\Desktop\Continue Facemoods Installation.lnk
- %TEMP%\ish32328544\images\progress-bg.png
- %TEMP%\ish32328544\images\buttons.png
- %TEMP%\ish32328544\images\box-facemoods.jpg
- %TEMP%\0001A7C4.log
- %TEMP%\ish32328544\license_EN.txt
- %TEMP%\ish32328544\ie6_style.css
- %TEMP%\ish32328544\iepngfix.htc
- %TEMP%\ish32328544\facemoods.ico
- %TEMP%\ish32328544\images\logo.jpg
- %TEMP%\ish32328544\images\._box-facemoods.jpg
- %TEMP%\0001BB6B.log
- %TEMP%\0001CEC4.log
- %TEMP%\ish32328544\bootstrap_47851.html
- %TEMP%\0001A7C4.log
- %TEMP%\0001B3E9.log
- %TEMP%\0001BA04.log
- 'i.###emoods.com':80
- 'rp.####rammersupply.com':80
- 'vc.####moodsreport.com':80
- i.###emoods.com/facemoods.cis
- rp.####rammersupply.com/cgi-bin/utils/IP2CC.psc
- vc.####moodsreport.com/?pc###########
- DNS ASK i.###emoods.com
- DNS ASK rp.####rammersupply.com
- DNS ASK vc.####moodsreport.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''