Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '%PROGRAM_FILES%\Coupon Marvel\bin\CouponMarvel32.dll '
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- %TEMP%\nsq2.tmp\System.dll
- %PROGRAM_FILES%\Coupon Marvel\bin\CouponMarvel32.dll
- %PROGRAM_FILES%\Coupon Marvel\bin\CouponMarvel.exe
- %TEMP%\nsq2.tmp\NSISHelper.dll
- %TEMP%\nsq2.tmp\UserInfo.dll
- %PROGRAM_FILES%\Coupon Marvel\Uninstall.exe
- %TEMP%\nsq2.tmp\UserInfo.dll
- %TEMP%\nsq2.tmp\System.dll
- %TEMP%\nsq2.tmp\NSISHelper.dll
- 'pi##ght.com':443
- 'bi###ocker.com':443
- DNS ASK pi##ght.com
- DNS ASK bi###ocker.com