Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = 'filesafe.dll'
- '<SYSTEM32>\ntvdm.exe' -f -i1
- '<SYSTEM32>\regsvr32.exe' /s /u "%PROGRAM_FILES%\snav\snav.dll"
- '<SYSTEM32>\regsvr32.exe' /s /u "<SYSTEM32>\snav.dll"
- <SYSTEM32>\snav.dll
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- <SYSTEM32>\iebarLite.exe
- <SYSTEM32>\unz32dll.dll
- <SYSTEM32>\HintPop.log
- <SYSTEM32>\HintBrowser.dll
- <SYSTEM32>\filesafe.dll
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- <SYSTEM32>\snav.dll
- DNS ASK sp##.#intsoft.net
- 'sp##.#intsoft.net':8888
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-c88.c8c.380001'