Техническая информация
- %TEMP%\low\hoc8smoh.exe
- %TEMP%\shopathome_toolbar_installer.exe
- %TEMP%\low\4ri4sqv9.tmp
- %ProgramFiles(x86)%\selectrebates\selectrebatesdownload.exe
- %LOCALAPPDATA%\microsoft\windows\history\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %TEMP%\low\hoc8smoh.exe
- %TEMP%\shopathome_toolbar_installer.exe
- %TEMP%\low\4ri4sqv9.tmp
- %TEMP%\low\4ri4sqv9.tmp
- DNS ASK tb##.#hopathome.com
- ClassName: 'SelectRebatesClass' WindowName: ''
- ClassName: '' WindowName: 'SAH Select Agent'
- '%TEMP%\shopathome_toolbar_installer.exe' -t:"%TEMP%\Low\HOC8SMOH.exe" -d:"%ProgramFiles(x86)%\SelectRebates\SelectRebatesDownload.exe" -i:"%TEMP%\Low\4RI4SQV9.tmp"
- '%ProgramFiles(x86)%\selectrebates\selectrebatesdownload.exe'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' "199.221.131.86/RequestHandler.ashx?MfcISAPICommand=installstatus¶m=%20%01%01%00cIh8TWZadr7iiDTOi6UtcZD2-yUq841bhSicHeQ5DE1O6io0MfkL7CaYiOFD_Q4zpckL6mtW1_Y9KMxaXIiLnDchpXOsOevdYDS7nlW6PgGYa...' (со скрытым окном)
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' "199.221.131.86/RequestHandler.ashx?MfcISAPICommand=installstatus¶m=%20%01%01%00cIh8TWZadr7iiDTOi6UtcZD2-yUq841bhSicHeQ5DE1O6io0MfkL7CaYiOFD_Q4zpckL6mtW1_Y9KMxaXIiLnDchpXOsOevdYDS7nlW6PgGYa...