Техническая информация
- "%TEMP%\reimage-1.5.0.6_tmp.exe" (загружен из сети Интернет)
- %TEMP%\nss4.tmp\KillProc.dll
- %TEMP%\nss4.tmp\UserInfo.dll
- %TEMP%\downloader log.txt
- %TEMP%\nss4.tmp\ioSpecial.ini
- %TEMP%\nss4.tmp\InstallOptions.dll
- %TEMP%\nss4.tmp\modern-header.bmp
- %TEMP%\nss4.tmp\modern-wizard.bmp
- %TEMP%\nss4.tmp\System.dll
- %TEMP%\nss4.tmp\inetc.dll
- %TEMP%\nst2.tmp\NSISdl.dll
- %TEMP%\reimage-1.5.0.6.exe
- %TEMP%\reimage-1.5.0.6_tmp.exe
- %TEMP%\nss4.tmp\LogEx.dll
- %TEMP%\ack.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\events4[1].php
- %TEMP%\nst2.tmp\NSISdl.dll
- 'www.re##age.com':80
- 've####nstring.com':80
- www.re##age.com/events4.php?ve##################################################
- ve####nstring.com/version/check.php?ve##########################
- DNS ASK www.re##age.com
- DNS ASK ve####nstring.com
- ClassName: 'Shell_TrayWnd' WindowName: ''