Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\20121023.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\20121023j.lnk
- C:\Outn\meandme.exe
- %TEMP%\install_flashplayer11x32ax_mssd_aih.exe {RemoveFile:C:\Outn\install_flashplayer11x32ax_mssd_aih.exe}
- C:\Outn\install_flashplayer11x32ax_mssd_aih.exe
- C:\Outn\axsdfrg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\actionlist[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\custom-form-elements[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\actionregistryvaluecheck[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\actionactionlist[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\language[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bgHeaderError[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iconHeader[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\index[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\actionregistrykeypathcheck[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\actionlaunchflashplayer[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\actionairappexists[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\actionlaunchadobe[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\actionlaunchchrome[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\actionairappinstall[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\actiongccheck[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\actioncheckuninstall[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\actionairruntimeexists[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\actiongtbcheck[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\buttonRight[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bgDownloadBarError[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bgDownloadBarFull[1].png
- %TEMP%\AIH.6a1fee5264f4716d98606b31074f7a8b24f12835\launcher.bundle.partial
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\buttonLeft[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\buttonRight[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\buttonLeft[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\buttonCenter[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\buttonCenter[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bgDownloadBarEmpty[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\buttonRightFinished[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\buttonCenterFinished[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bgBody[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bgCheckbox[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\buttonLeftFinished[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\iconBlank[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iconError[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bundles[1].json
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\iconComplete[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\where[1].php
- %WINDIR%DLL\num.txt
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6
- %WINDIR%DLL\20121023\20121023.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\craigslist[1]
- %TEMP%\install_flashplayer11x32ax_mssd_aih.exe
- %WINDIR%Backup\num.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\craigslist[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\newuser[1].htm
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6
- C:\Outn\axsdfrg.exe
- C:\Outn\client.exe
- C:\Outn\install_flashplayer11x32ax_mssd_aih.exe
- C:\Outn\meandme.exe
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
- %WINDIR%Backup\20121023\20121023.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\httpdownload[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bundleloader[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\app[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\skinwindow[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\adobe[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\actiondownloadadobe[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\actionlaunch[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ping[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\actiondownload[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\host[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\rt[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wpad[1].dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\wpad[1].dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\wpad[1].dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\index[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\json2[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\interop[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\jshelper[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\default[1].css
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\buttonCenter[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\buttonRight[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\buttonLeft[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\wpad[1].dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\craigslist[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\wpad[1].dat
- C:\Outn\install_flashplayer11x32ax_mssd_aih.exe
- %TEMP%\AIH.6a1fee5264f4716d98606b31074f7a8b24f12835\launcher.bundle.partial в %TEMP%\AIH.6a1fee5264f4716d98606b31074f7a8b24f12835\launcher.bundle
- 'localhost':1040
- 'localhost':1047
- 'www.my###il3.info':80
- 'localhost':1060
- 'localhost':1054
- 'localhost':1055
- 'www.cr###slist.com':80
- 'cs######0-crl.verisign.com':80
- 'crl.verisign.com':80
- 'wp#d':80
- 'localhost':1043
- 'www.tr###finc.com':80
- 'localhost':1041
- www.tr###finc.com/byip/where.php
- www.cr###slist.com/
- www.my###il3.info/dt/rt.php?we######################################
- cs######0-crl.verisign.com/CSC3-2010.crl
- wp#d/wpad.dat
- crl.verisign.com/pca3.crl
- crl.verisign.com/pca3-g5.crl
- DNS ASK www.tr###finc.com
- DNS ASK www.cr###slist.com
- DNS ASK www.my###il3.info
- DNS ASK wp#d
- DNS ASK crl.verisign.com
- DNS ASK cs######0-crl.verisign.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''