Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'maj_m1988' = '%PROGRAM_FILES%\m1988\maj.exe'
- %PROGRAM_FILES%\m1988\esp_bjr.exe
- %PROGRAM_FILES%\m1988\maj.exe
- <SYSTEM32>\regsvr32.exe /s "%PROGRAM_FILES%\m1988\ie100.dll"
- firefox.exe
- %PROGRAM_FILES%\m1988\au_revoir.exe
- %PROGRAM_FILES%\m1988\ff\chrome\content\overlay.xul
- %PROGRAM_FILES%\m1988\ff\chrome\content\main.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\prefs.js.orig
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\esp_bjr_1[1].php
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- %TEMP%\nsk2.tmp\Processes.dll
- %PROGRAM_FILES%\m1988\esp_bjr.exe
- %PROGRAM_FILES%\m1988\esp_arv.exe
- %PROGRAM_FILES%\m1988\ch.crx
- %PROGRAM_FILES%\m1988\ie100.dll
- %PROGRAM_FILES%\m1988\ff\install.rdf
- %PROGRAM_FILES%\m1988\ff\chrome.manifest
- %PROGRAM_FILES%\m1988\maj.exe
- %TEMP%\nsk2.tmp\Processes.dll
- 'm1##8.ae':80
- 'localhost':1035
- m1##8.ae/esp_bjr_1.php
- DNS ASK m1##8.ae
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: 'Shell_TrayWnd'
- ClassName: 'Indicator' WindowName: ''