Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'JSIModule' = 'rundll32.exe "%TEMP%\JS1.tmp",InstallHook'
- <SYSTEM32>\rundll32.exe "%TEMP%\JS1.tmp",InstallHook
- chrome.exe
- firefox.exe
- iexplore.exe
- %HOMEPATH%\Desktop\Profile Craze.lnk
- %TEMP%\JS1.tmp
- 'me###.#rofilecraze.com':80
- me###.#rofilecraze.com/misc/xml/install.xml
- DNS ASK me###.#rofilecraze.com
- '<IP-адрес в локальной сети>':1035
- ClassName: '' WindowName: ''