Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'v3ab4xua' = 'rundll32 "%WINDIR%\Downlo~1\v3ab4xua.dll",start'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'ff2' = 'rundll32 "%WINDIR%\Downlo~1\ff2.dll",Run'
- %TEMP%\mbdmrgk\setup.tmp
- %TEMP%\mbdmrgk\minidll.dll.zgx.tmp
- %TEMP%\mbdmrgk\minidll.dll.zgx
- %TEMP%\mbdmrgk\up.dll.zgx.tmp
- %TEMP%\mbdmrgk\up.dll.zgx
- %TEMP%\mbdmrgk\_uninstall
- %WINDIR%\Downloaded Program Files\v3ab4xua.dll
- %WINDIR%\0811b04a
- %WINDIR%\Downloaded Program Files\ff2.dll
- %WINDIR%\817-8074
- %TEMP%\mbdmrgk\minidll.dll.zgx.tmp
- %TEMP%\mbdmrgk\up.dll.zgx.tmp
- %TEMP%\mbdmrgk\setup.tmp
- %TEMP%\mbdmrgk\minidll.dll
- %TEMP%\mbdmrgk\up.dll
- %TEMP%\mbdmrgk\_uninstall
- %TEMP%\mbdmrgk\minidll.dll.zgx в %TEMP%\mbdmrgk\minidll.dll
- %TEMP%\mbdmrgk\up.dll.zgx в %TEMP%\mbdmrgk\up.dll
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\Downlo~1\v3ab4xua.dll",start' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\Downlo~1\ff2.dll",Run' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\Downlo~1\v3ab4xua.dll",start
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\Downlo~1\ff2.dll",Run