Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Orbit.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\Orbitdownloader\orbitnet.exe' = '%ProgramFiles%\Orbitdo...
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\Orbitdownloader\orbitdm.exe' = '%ProgramFiles%\Orbitdow...
- firefox.exe
- iexplore.exe
- %ProgramFiles%\Orbitdownloader\language\is-42NGS.tmp
- %ProgramFiles%\Orbitdownloader\language\is-2GV2A.tmp
- %ProgramFiles%\Orbitdownloader\language\is-KSPJC.tmp
- %ProgramFiles%\Orbitdownloader\language\is-CUJH8.tmp
- %ProgramFiles%\Orbitdownloader\language\is-BJEPM.tmp
- %ProgramFiles%\Orbitdownloader\language\is-0FKG5.tmp
- %ProgramFiles%\Orbitdownloader\language\is-E781U.tmp
- %ProgramFiles%\Orbitdownloader\language\is-RGNFU.tmp
- %ProgramFiles%\Orbitdownloader\language\is-70D5E.tmp
- %ProgramFiles%\Orbitdownloader\language\is-BBMO1.tmp
- %ProgramFiles%\Orbitdownloader\language\is-54THB.tmp
- %ProgramFiles%\Orbitdownloader\language\is-7TOP5.tmp
- %ProgramFiles%\Orbitdownloader\language\is-UP4H8.tmp
- %ProgramFiles%\Orbitdownloader\language\is-7J7F7.tmp
- %ProgramFiles%\Orbitdownloader\language\is-V19IH.tmp
- %ProgramFiles%\Orbitdownloader\language\is-0U9L7.tmp
- %ProgramFiles%\Orbitdownloader\language\is-LVAPQ.tmp
- %ProgramFiles%\Orbitdownloader\language\is-VHGCJ.tmp
- %ProgramFiles%\Orbitdownloader\language\is-4UON5.tmp
- %ALLUSERSPROFILE%\Start Menu\Programs\Orbit\Uninstall Orbit.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Orbit\Homepage.url
- %ProgramFiles%\Orbitdownloader\is-2JKAL.tmp
- %ALLUSERSPROFILE%\Start Menu\Programs\Orbit\Orbit.lnk
- %HOMEPATH%\Desktop\Orbit.lnk
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\s2r4
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\orbit_ffext@orbitdownloader
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
- %ProgramFiles%\Orbitdownloader\unins000.dat
- %ProgramFiles%\Orbitdownloader\is-093PO.tmp
- %ProgramFiles%\Orbitdownloader\language\is-LMEQA.tmp
- %ProgramFiles%\Orbitdownloader\addons\is-BIK7Q.tmp
- %ProgramFiles%\Orbitdownloader\language\is-9QS84.tmp
- %ProgramFiles%\Orbitdownloader\language\is-Q6599.tmp
- %ProgramFiles%\Orbitdownloader\addons\orbitff\is-8L44G.tmp
- %ProgramFiles%\Orbitdownloader\is-J4VB2.tmp
- %ProgramFiles%\Orbitdownloader\is-D433Q.tmp
- %ProgramFiles%\Orbitdownloader\addons\orbitff\is-AF3I4.tmp
- %ProgramFiles%\Orbitdownloader\addons\orbitff\chrome\is-NQODI.tmp
- %ProgramFiles%\Orbitdownloader\language\is-NEFEA.tmp
- %ProgramFiles%\Orbitdownloader\is-QM0KS.tmp
- %ProgramFiles%\Orbitdownloader\is-9QR8J.tmp
- %ProgramFiles%\Orbitdownloader\is-IB3L1.tmp
- %ProgramFiles%\Orbitdownloader\is-NF35P.tmp
- %ProgramFiles%\Orbitdownloader\is-4ECKE.tmp
- %ProgramFiles%\Orbitdownloader\is-CI5AM.tmp
- %ProgramFiles%\Orbitdownloader\is-RF0DR.tmp
- %ProgramFiles%\Orbitdownloader\is-TA8TU.tmp
- %ProgramFiles%\Orbitdownloader\is-KEPKM.tmp
- %ProgramFiles%\Orbitdownloader\is-9MQET.tmp
- %TEMP%\is-U2NRI.tmp\is-FKG51.tmp
- %TEMP%\is-IHP0P.tmp\_isetup\_RegDLL.tmp
- %TEMP%\RarSFX0\Orbit_Install.exe
- %TEMP%\RarSFX0\SetupOrbit.exe
- %TEMP%\is-IHP0P.tmp\_isetup\_shfoldr.dll
- %ProgramFiles%\Orbitdownloader\is-9VBLL.tmp
- %ProgramFiles%\Orbitdownloader\is-H6VD5.tmp
- %TEMP%\is-IHP0P.tmp\saction.dll
- %APPDATA%\Orbit\Conf.dat
- %ProgramFiles%\Orbitdownloader\language\is-VQ4DO.tmp
- %ProgramFiles%\Orbitdownloader\language\is-P5OVO.tmp
- %ProgramFiles%\Orbitdownloader\language\is-6JMSO.tmp
- %ProgramFiles%\Orbitdownloader\language\is-MHNL7.tmp
- %ProgramFiles%\Orbitdownloader\language\is-F7FDT.tmp
- %ProgramFiles%\Orbitdownloader\language\is-KKO36.tmp
- %ProgramFiles%\Orbitdownloader\language\is-UDSI6.tmp
- %ProgramFiles%\Orbitdownloader\language\is-PHLPT.tmp
- %ProgramFiles%\Orbitdownloader\language\is-8QCG8.tmp
- %ProgramFiles%\Orbitdownloader\language\is-SFLG4.tmp
- %ProgramFiles%\Orbitdownloader\is-CEM8T.tmp
- %ProgramFiles%\Orbitdownloader\language\is-9IB3U.tmp
- %ProgramFiles%\Orbitdownloader\is-VOJ7S.tmp
- %ProgramFiles%\Orbitdownloader\is-FPHTB.tmp
- %ProgramFiles%\Orbitdownloader\language\is-KFMHA.tmp
- %ProgramFiles%\Orbitdownloader\language\is-3OEDF.tmp
- %ProgramFiles%\Orbitdownloader\language\is-8UJC1.tmp
- %ProgramFiles%\Orbitdownloader\language\is-N87JI.tmp
- %ProgramFiles%\Orbitdownloader\language\is-D6SR0.tmp
- %TEMP%\is-IHP0P.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-U2NRI.tmp\is-FKG51.tmp
- %TEMP%\is-IHP0P.tmp\saction.dll
- %TEMP%\is-IHP0P.tmp\_isetup\_RegDLL.tmp
- %ProgramFiles%\Orbitdownloader\language\is-BBMO1.tmp в %ProgramFiles%\Orbitdownloader\language\obplk.ini
- %ProgramFiles%\Orbitdownloader\language\is-LVAPQ.tmp в %ProgramFiles%\Orbitdownloader\language\obnor.ini
- %ProgramFiles%\Orbitdownloader\language\is-0U9L7.tmp в %ProgramFiles%\Orbitdownloader\language\obnld.ini
- %ProgramFiles%\Orbitdownloader\language\is-KSPJC.tmp в %ProgramFiles%\Orbitdownloader\language\obptb.ini
- %ProgramFiles%\Orbitdownloader\language\is-2GV2A.tmp в %ProgramFiles%\Orbitdownloader\language\obrus.ini
- %ProgramFiles%\Orbitdownloader\language\is-42NGS.tmp в %ProgramFiles%\Orbitdownloader\language\obrom.ini
- %ProgramFiles%\Orbitdownloader\language\is-CUJH8.tmp в %ProgramFiles%\Orbitdownloader\language\obptg.ini
- %ProgramFiles%\Orbitdownloader\language\is-4UON5.tmp в %ProgramFiles%\Orbitdownloader\language\obmki.ini
- %ProgramFiles%\Orbitdownloader\language\is-7J7F7.tmp в %ProgramFiles%\Orbitdownloader\language\obhun.ini
- %ProgramFiles%\Orbitdownloader\language\is-UP4H8.tmp в %ProgramFiles%\Orbitdownloader\language\obhrv.ini
- %ProgramFiles%\Orbitdownloader\language\is-NEFEA.tmp в %ProgramFiles%\Orbitdownloader\language\obheb.ini
- %ProgramFiles%\Orbitdownloader\language\is-54THB.tmp в %ProgramFiles%\Orbitdownloader\language\obind.ini
- %ProgramFiles%\Orbitdownloader\language\is-VHGCJ.tmp в %ProgramFiles%\Orbitdownloader\language\obkor.ini
- %ProgramFiles%\Orbitdownloader\language\is-V19IH.tmp в %ProgramFiles%\Orbitdownloader\language\objpn.ini
- %ProgramFiles%\Orbitdownloader\language\is-7TOP5.tmp в %ProgramFiles%\Orbitdownloader\language\obita.ini
- %ProgramFiles%\Orbitdownloader\language\is-BJEPM.tmp в %ProgramFiles%\Orbitdownloader\language\obsky.ini
- %ProgramFiles%\Orbitdownloader\addons\orbitff\chrome\is-NQODI.tmp в %ProgramFiles%\Orbitdownloader\addons\orbitff\chrome\orbit.jar
- %ProgramFiles%\Orbitdownloader\addons\orbitff\is-AF3I4.tmp в %ProgramFiles%\Orbitdownloader\addons\orbitff\install.rdf
- %ProgramFiles%\Orbitdownloader\addons\orbitff\is-8L44G.tmp в %ProgramFiles%\Orbitdownloader\addons\orbitff\chrome.manifest
- %ProgramFiles%\Orbitdownloader\is-J4VB2.tmp в %ProgramFiles%\Orbitdownloader\saction.dll
- %ProgramFiles%\Orbitdownloader\is-2JKAL.tmp в %ProgramFiles%\Orbitdownloader\Grab.exe
- %ProgramFiles%\Orbitdownloader\is-093PO.tmp в %ProgramFiles%\Orbitdownloader\GrabDll.dll
- %ProgramFiles%\Orbitdownloader\is-D433Q.tmp в %ProgramFiles%\Orbitdownloader\winfile.dll
- %ProgramFiles%\Orbitdownloader\addons\is-BIK7Q.tmp в %ProgramFiles%\Orbitdownloader\addons\nporbit.dll
- %ProgramFiles%\Orbitdownloader\language\is-0FKG5.tmp в %ProgramFiles%\Orbitdownloader\language\obswe.ini
- %ProgramFiles%\Orbitdownloader\language\is-70D5E.tmp в %ProgramFiles%\Orbitdownloader\language\obsrb.ini
- %ProgramFiles%\Orbitdownloader\language\is-RGNFU.tmp в %ProgramFiles%\Orbitdownloader\language\obsqi.ini
- %ProgramFiles%\Orbitdownloader\language\is-E781U.tmp в %ProgramFiles%\Orbitdownloader\language\obtha.ini
- %ProgramFiles%\Orbitdownloader\language\is-LMEQA.tmp в %ProgramFiles%\Orbitdownloader\language\obvit.ini
- %ProgramFiles%\Orbitdownloader\language\is-Q6599.tmp в %ProgramFiles%\Orbitdownloader\language\obukr.ini
- %ProgramFiles%\Orbitdownloader\language\is-9QS84.tmp в %ProgramFiles%\Orbitdownloader\language\obtrk.ini
- %ProgramFiles%\Orbitdownloader\is-CI5AM.tmp в %ProgramFiles%\Orbitdownloader\GrabKernel.dll
- %ProgramFiles%\Orbitdownloader\is-KEPKM.tmp в %ProgramFiles%\Orbitdownloader\GrabPro.dll
- %ProgramFiles%\Orbitdownloader\is-TA8TU.tmp в %ProgramFiles%\Orbitdownloader\orbitcth.dll
- %ProgramFiles%\Orbitdownloader\is-RF0DR.tmp в %ProgramFiles%\Orbitdownloader\Lang.ini
- %ProgramFiles%\Orbitdownloader\is-CEM8T.tmp в %ProgramFiles%\Orbitdownloader\siteinfo.ini
- %ProgramFiles%\Orbitdownloader\is-FPHTB.tmp в %ProgramFiles%\Orbitdownloader\banurl.ini
- %ProgramFiles%\Orbitdownloader\is-VOJ7S.tmp в %ProgramFiles%\Orbitdownloader\changelog.txt
- %ProgramFiles%\Orbitdownloader\is-4ECKE.tmp в %ProgramFiles%\Orbitdownloader\orbitmxt.dll
- %ProgramFiles%\Orbitdownloader\is-9MQET.tmp в %ProgramFiles%\Orbitdownloader\ssleay32.dll
- %ProgramFiles%\Orbitdownloader\is-H6VD5.tmp в %ProgramFiles%\Orbitdownloader\libeay32.dll
- %ProgramFiles%\Orbitdownloader\is-9VBLL.tmp в %ProgramFiles%\Orbitdownloader\unins000.exe
- %ProgramFiles%\Orbitdownloader\is-IB3L1.tmp в %ProgramFiles%\Orbitdownloader\orbitdm.exe
- %ProgramFiles%\Orbitdownloader\is-9QR8J.tmp в %ProgramFiles%\Orbitdownloader\orbitnet.exe
- %ProgramFiles%\Orbitdownloader\is-QM0KS.tmp в %ProgramFiles%\Orbitdownloader\idht.dll
- %ProgramFiles%\Orbitdownloader\is-NF35P.tmp в %ProgramFiles%\Orbitdownloader\download.dll
- %ProgramFiles%\Orbitdownloader\language\is-9IB3U.tmp в %ProgramFiles%\Orbitdownloader\language\obafr.ini
- %ProgramFiles%\Orbitdownloader\language\is-F7FDT.tmp в %ProgramFiles%\Orbitdownloader\language\obeso.ini
- %ProgramFiles%\Orbitdownloader\language\is-P5OVO.tmp в %ProgramFiles%\Orbitdownloader\language\obesn.ini
- %ProgramFiles%\Orbitdownloader\language\is-VQ4DO.tmp в %ProgramFiles%\Orbitdownloader\language\obeng.ini
- %ProgramFiles%\Orbitdownloader\language\is-PHLPT.tmp в %ProgramFiles%\Orbitdownloader\language\obesv.ini
- %ProgramFiles%\Orbitdownloader\language\is-UDSI6.tmp в %ProgramFiles%\Orbitdownloader\language\obfra.ini
- %ProgramFiles%\Orbitdownloader\language\is-KKO36.tmp в %ProgramFiles%\Orbitdownloader\language\obfin.ini
- %ProgramFiles%\Orbitdownloader\language\is-8QCG8.tmp в %ProgramFiles%\Orbitdownloader\language\obfar.ini
- %ProgramFiles%\Orbitdownloader\language\is-MHNL7.tmp в %ProgramFiles%\Orbitdownloader\language\obell.ini
- %ProgramFiles%\Orbitdownloader\language\is-D6SR0.tmp в %ProgramFiles%\Orbitdownloader\language\obcat.ini
- %ProgramFiles%\Orbitdownloader\language\is-N87JI.tmp в %ProgramFiles%\Orbitdownloader\language\obbgr.ini
- %ProgramFiles%\Orbitdownloader\language\is-KFMHA.tmp в %ProgramFiles%\Orbitdownloader\language\obara.ini
- %ProgramFiles%\Orbitdownloader\language\is-3OEDF.tmp в %ProgramFiles%\Orbitdownloader\language\obchs.ini
- %ProgramFiles%\Orbitdownloader\language\is-6JMSO.tmp в %ProgramFiles%\Orbitdownloader\language\obdeu.ini
- %ProgramFiles%\Orbitdownloader\language\is-SFLG4.tmp в %ProgramFiles%\Orbitdownloader\language\obcsy.ini
- %ProgramFiles%\Orbitdownloader\language\is-8UJC1.tmp в %ProgramFiles%\Orbitdownloader\language\obcht.ini
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\prefs.js
- 'or####ownloader.com':80
- 'localhost':1038
- http://www.or####ownloader.com/Grab-Pro.htm?r=####### via or####ownloader.com
- http://www.or####ownloader.com/Grab-Pro.htm?r=####### via localhost
- DNS ASK www.or####ownloader.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'orbitdm_app' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\is-U2NRI.tmp\is-FKG51.tmp' /SL4 $2010C "%TEMP%\RarSFX0\SetupOrbit.exe" 2059596 52736 /VERYSILENT
- '%TEMP%\RarSFX0\SetupOrbit.exe' /VERYSILENT
- '%TEMP%\RarSFX0\Orbit_Install.exe'
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Orbitdownloader\GrabPro.dll"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Orbitdownloader\orbitmxt.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Orbitdownloader\orbitcth.dll"