Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\flashget_15938_1.exe' = '%TEMP%\flashget_15938_1.exe:*:Enabled:fg_ol_setup'
- '%TEMP%\flashget_15938_1.exe'
- '<SYSTEM32>\wscript.exe' %TEMP%\~DF17BD.tmp.vbs
- %TEMP%\nsx2.tmp\inetc.dll
- %TEMP%\nsx2.tmp\Math.dll
- %TEMP%\~DF17BD.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\nsis[1].asp
- %TEMP%\nsx2.tmp\System.dll
- %TEMP%\flashget_15938_1.exe
- %TEMP%\nsx2.tmp\KillProcDLL.dll
- %TEMP%\~DF17BD.tmp.vbs
- %TEMP%\nsx2.tmp\FindProcDLL.dll
- %TEMP%\nsx2.tmp\KillProcDLL.dll
- %TEMP%\nsx2.tmp\Math.dll
- %TEMP%\nsx2.tmp\System.dll
- %TEMP%\nsx2.tmp\inetc.dll
- %TEMP%\~DF17BD.tmp.vbs
- %TEMP%\~DF17BD.tmp
- %TEMP%\nsx2.tmp\FindProcDLL.dll
- 'st##.66233.net':80
- 'ol####.flashget.com':80
- 's4.##ashget.com':80
- st##.66233.net/nsis.asp?ID########################
- ol####.flashget.com/ver7/4C3EC3BD15C5060974C639D594156885/941BCE341E93226F66985372A583A21F/clickrun/15938/PST|flashget_15938_1.exe|<Служебное имя>.exe|<Служебное имя>.exe|cmd.exe|
- s4.##ashget.comhttp://s4.flashget.com/fg4/sul
- DNS ASK ol####.flashget.com
- DNS ASK st##.66233.net
- DNS ASK p2#####gji.flashget.com
- DNS ASK s4.##ashget.com
- 'p2#####gji.flashget.com':5555
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'