Техническая информация
- '<Текущая директория>\local\stubexe\0x109D77BB302AD254\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8.tmp" "%TEMP%\CSC7.tmp"
- '<Текущая директория>\local\stubexe\0x481929D124F74F16\csc.exe' /noconfig /fullpaths @"%TEMP%\1lngmctc.cmdline"
- '<Текущая директория>\local\stubexe\0x109D77BB302AD254\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA.tmp" "%TEMP%\CSC9.tmp"
- '<Текущая директория>\local\stubexe\0xC07DA1B6D546ED57\FreemakeVideoDownloader.exe'
- '<Текущая директория>\local\stubexe\0x0DE76CFC1EBA2B0C\FreemakeVD.exe'
- '<Текущая директория>\local\stubexe\0x481929D124F74F16\csc.exe' /noconfig /fullpaths @"%TEMP%\josqgurq.cmdline"
- <Текущая директория>\roaming\modified\@APPDATACOMMON@\Freemake\FreemakeVideoDownloader\SummaryLog.txt
- %TEMP%\Cab5.tmp
- %TEMP%\Cab3.tmp
- %TEMP%\josqgurq.0.cs
- <Текущая директория>\roaming\modified\@PROGRAMFILESX86@\Freemake\Freemake Video Downloader\trace.log
- <Текущая директория>\roaming\modified\@APPDATACOMMON@\Freemake\FreemakeVideoDownloader\3004.txt
- %TEMP%\Cab1.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
- <Текущая директория>\local\stubexe\0x0DE76CFC1EBA2B0C\FreemakeVD.exe.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\X86_Nullsoft.NSIS.exehead@1.0.0.0.manifest.__tmp__
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
- %TEMP%\josqgurq.cmdline
- %TEMP%\1lngmctc.out
- %TEMP%\1lngmctc.cmdline
- %TEMP%\1lngmctc.0.cs
- %TEMP%\1lngmctc.dll
- %TEMP%\RESA.tmp
- %TEMP%\CSC9.tmp
- <Текущая директория>\roaming\modified\@APPDATACOMMON@\Freemake\FreemakeVideoDownloader\Statistics.txt
- %TEMP%\CSC7.tmp
- <Текущая директория>\local\stubexe\0x481929D124F74F16\csc.exe.__tmp__
- %TEMP%\josqgurq.out
- %TEMP%\josqgurq.dll
- %TEMP%\RES8.tmp
- <Текущая директория>\local\stubexe\0x109D77BB302AD254\cvtres.exe.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMTransformBase.dll_0x8cbd578093028cb846cb01b1a3f1e18b.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaUtils.dll_0x96c8cd190ae328b3508e7aac44701100.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaSource.dll_0x58326ddd62f9069877c09dcc5d601309.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVD.exe_0x5f744c942368597cb9d6bd396befd3c3.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeUOs.exe_0x0175fd4bad7620d3e0ef45912a357c2e.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMVideoConverter.dll_0x159f8eafe93bbfe1d7fa54b51e6ac91e.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaFormats.dll_0x9905532dab037f8c43299a5816707b26.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\_MyApplication.app@1.0.0.0.manifest.__tmp__
- <Текущая директория>\local\stubexe\0xC07DA1B6D546ED57\FreemakeVideoDownloader.exe.__tmp__
- <Текущая директория>\xsandbox.bin.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\dotNetFx40_Client_setup.exe_0x61446fdd76788229d3ebaeabe84df38c.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\CaptureLibService.exe_0x119d4905baf436fac438ed5de40d1f41.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\MyApplication.app.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoDownloader.exe_0xda65e18023726a8ff0bd07d5185fc3af.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\x86_BoxStub@1.0.0.0.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\BoxStub.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\wpcap.dll_0x190fb481d293d85b507d071e75bcb05c.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\Nullsoft.NSIS.exehead.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\winpcap.exe_0x17474b8044fec8257531e97954516911.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\Packet.dll_0x1250bef11bfa086f772cd2a273bc036e.2.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\MiddleChainClient.exe_0xfdc1628bdf02c373b2722b317c78f2b3.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoSniff.exe_0x6da818ecbb8ec4f97592f5f028717bc5.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\uninstall.exe_0xef5522a600461d65dc3b9b91d5a27fa9.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\unins000.exe_0xe415cba9aaf626fca70f3060d25330bc.1.manifest.__tmp__
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\rpcapd.exe_0xb60f58f175de20a6739194e85b035178.1.manifest.__tmp__
- %TEMP%\josqgurq.0.cs
- %TEMP%\josqgurq.out
- %TEMP%\josqgurq.cmdline
- %TEMP%\CSC9.tmp
- %TEMP%\RESA.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wpad[1].dat
- %TEMP%\josqgurq.dll
- %TEMP%\Cab5.tmp
- %TEMP%\Cab3.tmp
- %TEMP%\Cab1.tmp
- %TEMP%\CSC7.tmp
- %TEMP%\RES8.tmp
- <SYSTEM32>\d3d9caps.dat
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\wpcap.dll_0x190fb481d293d85b507d071e75bcb05c.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\wpcap.dll_0x190fb481d293d85b507d071e75bcb05c.2.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\winpcap.exe_0x17474b8044fec8257531e97954516911.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\winpcap.exe_0x17474b8044fec8257531e97954516911.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\x86_BoxStub@1.0.0.0.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\x86_BoxStub@1.0.0.0.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\BoxStub.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_BoxStub@1.0.0.0\BoxStub.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\rpcapd.exe_0xb60f58f175de20a6739194e85b035178.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\rpcapd.exe_0xb60f58f175de20a6739194e85b035178.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\Packet.dll_0x1250bef11bfa086f772cd2a273bc036e.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\Packet.dll_0x1250bef11bfa086f772cd2a273bc036e.2.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\uninstall.exe_0xef5522a600461d65dc3b9b91d5a27fa9.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\uninstall.exe_0xef5522a600461d65dc3b9b91d5a27fa9.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\unins000.exe_0xe415cba9aaf626fca70f3060d25330bc.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\unins000.exe_0xe415cba9aaf626fca70f3060d25330bc.1.manifest
- <SYSTEM32>\d3d9caps.tmp в <SYSTEM32>\d3d9caps.dat
- <Текущая директория>\local\stubexe\0x0DE76CFC1EBA2B0C\FreemakeVD.exe.__tmp__ в <Текущая директория>\local\stubexe\0x0DE76CFC1EBA2B0C\FreemakeVD.exe
- <Текущая директория>\local\stubexe\0x109D77BB302AD254\cvtres.exe.__tmp__ в <Текущая директория>\local\stubexe\0x109D77BB302AD254\cvtres.exe
- <Текущая директория>\local\stubexe\0x481929D124F74F16\csc.exe.__tmp__ в <Текущая директория>\local\stubexe\0x481929D124F74F16\csc.exe
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\X86_Nullsoft.NSIS.exehead@1.0.0.0.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\X86_Nullsoft.NSIS.exehead@1.0.0.0.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\Nullsoft.NSIS.exehead.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\X86_Nullsoft.NSIS.exehead@1.0.0.0\Nullsoft.NSIS.exehead.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\dotNetFx40_Client_setup.exe_0x61446fdd76788229d3ebaeabe84df38c.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\dotNetFx40_Client_setup.exe_0x61446fdd76788229d3ebaeabe84df38c.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\CaptureLibService.exe_0x119d4905baf436fac438ed5de40d1f41.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\CaptureLibService.exe_0x119d4905baf436fac438ed5de40d1f41.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaSource.dll_0x58326ddd62f9069877c09dcc5d601309.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaSource.dll_0x58326ddd62f9069877c09dcc5d601309.2.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaFormats.dll_0x9905532dab037f8c43299a5816707b26.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaFormats.dll_0x9905532dab037f8c43299a5816707b26.2.manifest
- <Текущая директория>\local\stubexe\0xC07DA1B6D546ED57\FreemakeVideoDownloader.exe.__tmp__ в <Текущая директория>\local\stubexe\0xC07DA1B6D546ED57\FreemakeVideoDownloader.exe
- <Текущая директория>\xsandbox.bin.__tmp__ в <Текущая директория>\xsandbox.bin
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\MyApplication.app.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\MyApplication.app.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\_MyApplication.app@1.0.0.0.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\_MyApplication.app@1.0.0.0\_MyApplication.app@1.0.0.0.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoDownloader.exe_0xda65e18023726a8ff0bd07d5185fc3af.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoDownloader.exe_0xda65e18023726a8ff0bd07d5185fc3af.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVD.exe_0x5f744c942368597cb9d6bd396befd3c3.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVD.exe_0x5f744c942368597cb9d6bd396befd3c3.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\MiddleChainClient.exe_0xfdc1628bdf02c373b2722b317c78f2b3.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\MiddleChainClient.exe_0xfdc1628bdf02c373b2722b317c78f2b3.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoSniff.exe_0x6da818ecbb8ec4f97592f5f028717bc5.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeVideoSniff.exe_0x6da818ecbb8ec4f97592f5f028717bc5.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMTransformBase.dll_0x8cbd578093028cb846cb01b1a3f1e18b.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMTransformBase.dll_0x8cbd578093028cb846cb01b1a3f1e18b.2.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaUtils.dll_0x96c8cd190ae328b3508e7aac44701100.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMMediaUtils.dll_0x96c8cd190ae328b3508e7aac44701100.2.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeUOs.exe_0x0175fd4bad7620d3e0ef45912a357c2e.1.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FreemakeUOs.exe_0x0175fd4bad7620d3e0ef45912a357c2e.1.manifest
- %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMVideoConverter.dll_0x159f8eafe93bbfe1d7fa54b51e6ac91e.2.manifest.__tmp__ в %TEMP%\SPOON\CACHE\0x8D1494AB1ADE459C\sxs\Manifests\FMVideoConverter.dll_0x159f8eafe93bbfe1d7fa54b51e6ac91e.2.manifest
- 'www.download.windowsupdate.com':80
- 'se####.globalsign.com':80
- 'st###.spoon.net':443
- 'wp#d':80
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- http://se####.globalsign.com/cacert/gscodesignsha2g2.crt
- http://11#.#11.111.2/wpad.dat via wp#d
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- DNS ASK www.download.windowsupdate.com
- DNS ASK se####.globalsign.com
- DNS ASK st###.spoon.net
- DNS ASK wp#d
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''