Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- %TEMP%\nsw3469.tmp\uac.dll
- %TEMP%\nsw3469.tmp\system.dll
- %TEMP%\nsw3469.tmp\math.dll
- %WINDIR%\syswow64\-kaov-f2z-_-bwa.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\1067876
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\1072304
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\da48848188067b17c180188af3314d7e_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %TEMP%\nsw3469.tmp\nsb48a5.tmp
- %ProgramFiles(x86)%\mozilla firefox\extensions\{d56169d4-839d-83b6-b38b-32c4baefc919}\components\x5-hd_i_t0b_.dll
- %ProgramFiles(x86)%\mozilla firefox\extensions\{d56169d4-839d-83b6-b38b-32c4baefc919}\chrome.manifest
- %ProgramFiles(x86)%\mozilla firefox\extensions\{d56169d4-839d-83b6-b38b-32c4baefc919}\install.rdf
- %WINDIR%\syswow64\apfty_m_wo4_.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\1067876
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\1072304
- %TEMP%\nsw3469.tmp\math.dll
- %TEMP%\nsw3469.tmp\nsb48a5.tmp
- %TEMP%\nsw3469.tmp\system.dll
- %TEMP%\nsw3469.tmp\uac.dll
- DNS ASK gw.###mawega.com