Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NateSrv.exe' = '%PROGRAM_FILES%\NateSearch\NateSrv.exe'
- '%PROGRAM_FILES%\NateSearch\NateSrv.exe'
- '%TEMP%\009725_s.exe'
- '%PROGRAM_FILES%\NateSearch\NateSetup.exe'
- '<SYSTEM32>\regsvr32.exe' /s "%TEMP%\NateSearch.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\NateSearch\NateSearch.dll"
- %PROGRAM_FILES%\NateSearch\NateUninstall.exe
- %TEMP%\009725_s.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Ver_NateSearch_pc[1].txt
- %PROGRAM_FILES%\NateSearch\NateSearch.dll
- %PROGRAM_FILES%\NateSearch\NateSetup.exe
- %PROGRAM_FILES%\NateSearch\NateSrv.exe
- %PROGRAM_FILES%\NateSearch\NateSetup.exe
- 'si#####ch.linkprice.com':80
- 'mi#####p.linkprice.com':80
- si#####ch.linkprice.com/APP/NateSearch_PC/Ver_NateSearch_pc.txt
- mi#####p.linkprice.com/app/count.php?af###############################################################################################################################
- DNS ASK si#####ch.linkprice.com
- DNS ASK mi#####p.linkprice.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'