Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = 'filesafe.dll'
- '<SYSTEM32>\iebarLite.exe'
- '<SYSTEM32>\regsvr32.exe' /s /u "%PROGRAM_FILES%\snav\snav.dll"
- '<SYSTEM32>\regsvr32.exe' /s /u "<SYSTEM32>\snav.dll"
- <SYSTEM32>\iebarLite.exe
- %TEMP%\nsm2.tmp
- %PROGRAM_FILES%\snav\Snav.dll
- <SYSTEM32>\HintBrowser.dll
- <SYSTEM32>\HintPop.log
- <SYSTEM32>\unz32dll.dll
- <SYSTEM32>\filesafe.dll
- DNS ASK sp##.#intsoft.net
- 'sp##.#intsoft.net':8888