Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '%PROGRAM_FILES%\SProtector\sprote~1.dll'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- '<SYSTEM32>\rundll32.exe' "%PROGRAM_FILES%\SProtector\sprotector.dll",__register@0
- firefox.exe
- iexplore.exe
- chrome.exe
- %PROGRAM_FILES%\SProtector\uninstall.exe
- %PROGRAM_FILES%\SProtector\sprotector.dll
- %TEMP%\nsm2.tmp\dllext.dll
- %TEMP%\nsm2.tmp\dllext.dll