Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ktacenc' = '%WINDIR%\ktacenc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'hjyxdll' = '%WINDIR%\hjyxdll.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows VisFx Components] 'Start' = '00000002'
- %WINDIR%\hbmqsvc.exe -i
- %WINDIR%\hjyxdll.exe
- %WINDIR%\ktacenc.exe
- <SYSTEM32>\thin-94-1-x-x.exe
- <SYSTEM32>\VFX602.exe
- <SYSTEM32>\InstallerV3.exe
- %WINDIR%\Explorer.EXE
- %WINDIR%\ofxnm.dat
- %TEMP%\nsn3.tmp
- %WINDIR%\ktacenc.exe
- %WINDIR%\hjyxdll.exe
- %WINDIR%\tfxnm.dat
- %WINDIR%\lupd.dat
- %TEMP%\nsm5.tmp
- %WINDIR%\nxui.dat
- C:\dbg.txt
- %WINDIR%\uid24.key
- %WINDIR%\sfxnm.dat
- %WINDIR%\hbmqsvc.exe
- <SYSTEM32>\InstallerV3.exe
- <SYSTEM32>\thin-94-1-x-x.exe
- <SYSTEM32>\VFX602.exe
- %WINDIR%\visfxun.exe
- %WINDIR%\sfwv.dat
- %TEMP%\nss4.tmp\nsisdl.dll
- %WINDIR%\ISSM0064.DAT
- %TEMP%\ExtractDLL.dll
- %WINDIR%\ktacenc.exe
- %WINDIR%\hjyxdll.exe
- %WINDIR%\hbmqsvc.exe
- %TEMP%\nsn3.tmp
- 'th#######.abetterinternet.com':80
- 'www.po###stop.com':80
- www.po###stop.com/dist/COMMCOS2.DLL_1.07.compress
- www.po###stop.com/SupportFiles/msxml3a.dll.compress
- th#######.abetterinternet.com/bi/servlet/ThinstallPre
- DNS ASK th#######.abetterinternet.com
- DNS ASK www.po###stop.com