Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ConvertFilesforFreeUpdt] 'Start' = '00000002'
- '%TEMP%\nsx2.tmp\VOPackage.exe' /start /ch=imz
- '%TEMP%\helper.exe' /S
- '%APPDATA%\VOPackage\VOPackage.exe' /ivs
- '%APPDATA%\VOPackage\VOPackage.exe' /qualify
- '%TEMP%\nsq7.tmp\ns9.tmp' %TEMP%\helper.exe /S
- '%TEMP%\nsx2.tmp\ConvertFilesforFree_8.25_Installmonetize3_release.exe' /S
- '%TEMP%\nsx2.tmp\SmartMediaConverterSetup.exe' /S /tpchannelid=Applonx03 /distid=1200486
- '%PROGRAM_FILES%\Convert Files for Free\ConvertFilesforFreeUpdt.exe'
- '%TEMP%\nsq7.tmp\ns8.tmp' %PROGRAM_FILES%\Convert Files for Free\ConvertFilesforFreeUpdt.exe -il
- '<SYSTEM32>\regsvr32.exe' "%PROGRAM_FILES%\Convert Files for Free\ConvertFilesforFree.dll" /s
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\r[2]
- %TEMP%\heu39T.nss
- %WINDIR%\Temp\ConvertFilesforFreeUpdt_update.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\r[2]
- %APPDATA%\VOPackage\VOPackage.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\r[2]
- %TEMP%\nsf11.tmp
- %APPDATA%\VOPackage\Uninstall.exe
- %HOMEPATH%\Start Menu\Programs\VOPackage\Configure.lnk
- %TEMP%\nspF.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\r[1]
- %TEMP%\nspF.tmp\WmiInspector.dll
- %TEMP%\nspF.tmp\t1.dll
- %TEMP%\b
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\r[1]
- %TEMP%\nspF.tmp\IpConfig.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\r[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\r[1]
- %TEMP%\nsk12.tmp\System.dll
- %TEMP%\nsx2.tmp\registry.dll
- %TEMP%\nsx2.tmp\manlib.dll
- %TEMP%\nsh15.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\r[3]
- %TEMP%\nsk12.tmp\IpConfig.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\r[4]
- %TEMP%\nsh15.tmp\IpConfig.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\r[3]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\r[3]
- %TEMP%\nsm14.tmp
- %TEMP%\nsh15.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\r[2]
- %TEMP%\nsk12.tmp\WmiInspector.dll
- %TEMP%\nsk12.tmp\t1.dll
- %TEMP%\nsh15.tmp\WmiInspector.dll
- %TEMP%\nsh15.tmp\t1.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\r[3]
- %TEMP%\nsk12.tmp\inetc.dll
- %TEMP%\nsq7.tmp\System.dll
- %TEMP%\nsq7.tmp\registry.dll
- %TEMP%\nsy5.tmp\nsJSON.dll
- %TEMP%\nsx2.tmp\ConvertFilesforFree_8.25_Installmonetize3_release.exe
- %TEMP%\nsq7.tmp\GetVersion.dll
- C:\END
- %PROGRAM_FILES%\Convert Files for Free\install.ico
- %TEMP%\nsq7.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mainInstall[1].htm
- %TEMP%\nsy5.tmp\blowfish.dll
- %TEMP%\nsy5.tmp\inetc.dll
- %TEMP%\nsx2.tmp\SmartMediaConverterSetup.exe
- %TEMP%\nsi4.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\json[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\json[1].htm
- %TEMP%\nsy5.tmp\res.log
- %TEMP%\nsy5.tmp\te.log
- %TEMP%\nsy5.tmp\System.dll
- %PROGRAM_FILES%\Convert Files for Free\ConvertFilesforFree.dll
- %PROGRAM_FILES%\File Type Helper\FileTypeHelper.exe
- %PROGRAM_FILES%\File Type Helper\uninstall.exe
- %PROGRAM_FILES%\File Type Helper\Magnifier_64.ico
- %PROGRAM_FILES%\File Type Helper\FileTypeHelper_assoc.exe
- %PROGRAM_FILES%\Convert Files for Free\uninstall.exe
- %TEMP%\nsaE.tmp
- %TEMP%\nspF.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\freefrogInstall[1].htm
- %TEMP%\nsx2.tmp\VOPackage.exe
- %TEMP%\nsq7.tmp\ns8.tmp
- %PROGRAM_FILES%\Convert Files for Free\ConvertFilesforFreeUpdt.exe
- %TEMP%\nsq7.tmp\SimpleSC.dll
- %TEMP%\nsq7.tmp\nsExec.dll
- %TEMP%\helper.exe
- %PROGRAM_FILES%\File Type Helper\FileTypeHelper_assoc.7z
- %TEMP%\nsbC.tmp\nsis7z.dll
- %TEMP%\nsq7.tmp\ns9.tmp
- %TEMP%\nsgB.tmp
- %TEMP%\nspF.tmp\inetc.dll
- %TEMP%\nspF.tmp\IpConfig.dll
- %TEMP%\nspF.tmp\System.dll
- %TEMP%\nsq7.tmp\registry.dll
- %TEMP%\nsq7.tmp\SimpleSC.dll
- %TEMP%\nsq7.tmp\System.dll
- %TEMP%\nspF.tmp\t1.dll
- %TEMP%\nsx2.tmp\registry.dll
- %TEMP%\nsx2.tmp\SmartMediaConverterSetup.exe
- %TEMP%\nsx2.tmp\VOPackage.exe
- %TEMP%\nspF.tmp\WmiInspector.dll
- %TEMP%\nsx2.tmp\ConvertFilesforFree_8.25_Installmonetize3_release.exe
- %TEMP%\nsx2.tmp\manlib.dll
- %TEMP%\nsq7.tmp\nsExec.dll
- %TEMP%\nsy5.tmp\inetc.dll
- %TEMP%\nsy5.tmp\nsJSON.dll
- %TEMP%\nsy5.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\json[1].htm
- %TEMP%\nsy5.tmp\res.log
- %TEMP%\nsy5.tmp\blowfish.dll
- %TEMP%\nsy5.tmp\te.log
- %TEMP%\nsq7.tmp\ns9.tmp
- %TEMP%\nsq7.tmp\GetVersion.dll
- %TEMP%\nsq7.tmp\inetc.dll
- %TEMP%\nsq7.tmp\ns8.tmp
- %PROGRAM_FILES%\File Type Helper\FileTypeHelper_assoc.7z
- %TEMP%\nsbC.tmp\nsis7z.dll
- 'da##.#iphysics.com':80
- 'www.co#####filesforfree.com':80
- 'sm################r02.smartmediaconverter00.smartmediaconverter.com':80
- da##.#iphysics.com/r?_=###################################################################################
- da##.#iphysics.com/r?_=###################################################################################################
- da##.#iphysics.com/r?_=###############################################################################
- www.co#####filesforfree.com/w/updater/u.php?ti#####################################################################################################################
- da##.#iphysics.com/r?_=################################################################################
- da##.#iphysics.com/r?_=##############################################################################
- www.co#####filesforfree.com/install/freefrogInstall
- www.co#####filesforfree.com/install/mainInstall
- sm################r02.smartmediaconverter00.smartmediaconverter.com/api/json
- DNS ASK da##.#iphysics.com
- DNS ASK www.co#####filesforfree.com
- DNS ASK sm################r02.smartmediaconverter00.smartmediaconverter.com
- ClassName: '#32770' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'