Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SelfPrivacy' = '"%PROGRAM_FILES%\SelfPrivacy\SelfPrivacy.exe" /run1'
- <SYSTEM32>\selfprivacy_liveon.exe /S
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- %PROGRAM_FILES%\SelfPrivacy\SelfPrivacyMon.exe
- %PROGRAM_FILES%\SelfPrivacy\SelfPrivacycfg.exe
- %PROGRAM_FILES%\SelfPrivacy\SelfPrivacy.exe
- %TEMP%\nsi4.tmp\KillProcDLL.dll
- %TEMP%\nsi4.tmp\DLLWaitForKillProgram.dll
- %TEMP%\nsi4.tmp\processes_second.dll
- %HOMEPATH%\Start Menu\Programs\јїЗБЗБ¶уАМ№цЅГ\јїЗБЗБ¶уАМ№цЅГ Б¦°Е.lnk
- %TEMP%\nsi4.tmp\IEFunctions.dll
- %HOMEPATH%\Start Menu\Programs\јїЗБЗБ¶уАМ№цЅГ\јїЗБЗБ¶уАМ№цЅГ.lnk
- %PROGRAM_FILES%\SelfPrivacy\partner.ini
- %PROGRAM_FILES%\SelfPrivacy\Uninstall.exe
- C:\DelUS.bat
- %TEMP%\nsi4.tmp\ChkClient.dll
- %TEMP%\nsi4.tmp\stack.dll
- <SYSTEM32>\selfprivacy_liveon.exe
- %TEMP%\nss3.tmp\SelfDelete.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\pcroomchk[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instchk[1].php
- %TEMP%\instpage.ini
- %TEMP%\nsi4.tmp\Ischeck.dll
- %TEMP%\temppage.ini
- %TEMP%\nsi4.tmp\IsVista.dll
- %TEMP%\instpage.ini
- %TEMP%\temppage.ini
- %TEMP%\nss3.tmp\SelfDelete.dll
- 'up####.#elfprivacy.co.kr':80
- 'localhost':1036
- up####.#elfprivacy.co.kr/instchk/instchk.php
- up####.#elfprivacy.co.kr/instchk/pcroomchk.php
- DNS ASK up####.#elfprivacy.co.kr
- '<IP-адрес в локальной сети>':1037