Техническая информация
- '<SYSTEM32>\conhost.exe' /C copy /b "%TEMP%\nsp2E32.tmp\" + "<SYSTEM32>\ieframe.dll" "%TEMP%\nsp2E32.tmp\"
- '<SYSTEM32>\taskhost.exe' /pid=0x654 /log
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8D16.tmp
- %HOMEPATH%\Downloads\en:Zone.Identifier
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC4.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\923A.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8EB0.tmp
- %TEMP%\etilqs_tqaGXsReO20niP4
- %HOMEPATH%\Downloads\2A7A.tmp
- %HOMEPATH%\Downloads\360F.tmp
- %HOMEPATH%\Downloads\20.jpg:Zone.Identifier
- %TEMP%\etilqs_d4vnIyYTTQ3rHfc
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\950A.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\LOG
- %TEMP%\etilqs_0frJcEj0gzIpUDj
- %APPDATA%\Roaming\Opera Software\Opera Stable\8E2C.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\AEF4.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96FF.tmp
- %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\CKM3HWUKF9C3Z9CYC0V2.temp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Meinvkankan\uninst.lnk
- %PROGRAM_FILES%\Meinvkankan\Uninstall.exe
- %TEMP%\nsp2E32.tmp\Inetc.dll
- %TEMP%\nsp2E32.tmp\3.ico
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\23BUYPX5\2[1].ico
- %TEMP%\nsp2E32.tmp\2.ico
- %TEMP%\nsp2E32.tmp\System.dll
- %TEMP%\nsp2E32.tmp\nsProcess.dll
- %TEMP%\nsp2E32.tmp\i.rar
- %TEMP%\nsp2E32.tmp\NSISdl.dll
- %HOMEPATH%\Desktop\Intrenet Explorer.lnk
- %TEMP%\etilqs_9QGqRargqN2BqdV
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\LOG
- %APPDATA%\Roaming\Opera Software\Opera Stable\History Provider Cache
- %APPDATA%\Roaming\Opera Software\Opera Stable\18BD.tmp
- <Служебный элемент>
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- %TEMP%\nsp2E32.tmp\ExecCmd.dll
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96EF.tmp~RFc976e.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\94F9.tmp~RFc96a3.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\97CB.tmp~RFcbd17.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RFcdf18.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\90D3.tmp~RFc9349.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RFbe34c.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8CE6.tmp~RFc8dae.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8E9F.tmp~RFc8f24.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC3.tmp~RFc8e1b.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\94F9.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\94F9.tmp~RFc96a3.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96FF.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96EF.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96EF.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\96EF.tmp~RFc976e.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\923A.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\90D3.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\90D3.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\90D3.tmp~RFc9349.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\950A.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\94F9.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\AEF4.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\97CB.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RFcdf18.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\8E2C.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Local State
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\97CB.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\97CB.tmp~RFcbd17.TMP
- %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\CKM3HWUKF9C3Z9CYC0V2.temp в %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\8548f632abe97aa3.customDestinations-ms
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8E9F.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8E9F.tmp~RFc8f24.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\18BD.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Preferences
- %HOMEPATH%\Downloads\2A7A.tmp в %HOMEPATH%\Downloads\20.jpg.opdownload
- %HOMEPATH%\Downloads\360F.tmp в %HOMEPATH%\Downloads\en.opdownload
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RFbe34c.TMP
- %HOMEPATH%\Downloads\20.jpg.opdownload в %HOMEPATH%\Downloads\20.jpg
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC4.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC3.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC3.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8DC3.tmp~RFc8e1b.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8EB0.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8E9F.tmp
- %HOMEPATH%\Downloads\en.opdownload в %HOMEPATH%\Downloads\en
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8D16.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8CE6.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8CE6.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\8CE6.tmp~RFc8dae.TMP
- 'i.##0.ru':80
- 'bi##.#ikimedia.org':80
- '93.##8.134.11':80
- 'ap#.###sys.opera.com':443
- 'au######te.geo.opera.com':443
- 'www.go##le.ru':80
- 'pc###ine.org.cn':80
- 'in#.###ol.sina.com.cn':80
- 'www.ic#.com':80
- 'si#####ck2.opera.com':80
- 'f.####anxinyuan.com':80
- i.##0.ru/2011/icons/rambler.ico
- bi##.#ikimedia.org/favicon/wikipedia.ico
- 93.##8.134.11/favicon.ico
- www.ic#.com/en
- f.####anxinyuan.com/<Служебное имя>.exe/20.jpg
- pc###ine.org.cn/2.ico
- in#.###ol.sina.com.cn/iplookup/iplookup.php
- si#####ck2.opera.com/?ho###############################################
- www.go##le.ru/favicon.ico
- si#####ck2.opera.com/?ho#########################################################
- DNS ASK sl####i.yandex.ru
- DNS ASK i.##0.ru
- DNS ASK bi##.#ikimedia.org
- DNS ASK dn#.##ftncsi.com
- DNS ASK ap#.###sys.opera.com
- DNS ASK au######te.geo.opera.com
- DNS ASK www.go##le.ru
- DNS ASK www.google.com
- DNS ASK pc###ine.org.cn
- DNS ASK in#.###ol.sina.com.cn
- DNS ASK si#####ck2.opera.com
- DNS ASK f.####anxinyuan.com
- DNS ASK www.ic#.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'CicLoaderWndClass' WindowName: ''
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Roaming\Opera Software\Opera Stable'