Техническая информация
- '%TEMP%\INS4.tmp' /SL3 $50036 %TEMP%\software.exe 3456612 3460464 61440
- '%TEMP%\software.exe'
- '%TEMP%\mySecureSurfer_no_chrome.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- firefox.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}\chrome\content\extension.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}\install.rdf
- %TEMP%\software.exe
- %TEMP%\is-FOHOR.tmp\_shfoldr.dll
- %TEMP%\INS4.tmp
- %TEMP%\nsb3.tmp\KillProcDLL.dll
- %TEMP%\mySecureSurfer_no_chrome.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}\bootstrap.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}\icon32.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}\icon.png
- %TEMP%\mySecureSurfer_no_chrome.exe
- %TEMP%\nsb3.tmp\KillProcDLL.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''