Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MyClearSearch Helper Service] 'Start' = '00000002'
- %TEMP%\kobf.exe
- %TEMP%\wrnriq.exe
- %TEMP%\ewihapau.exe
- %TEMP%\rvct.exe
- %PROGRAM_FILES%\MyClearSearch\MyClearSearchSvc.exe
- %TEMP%\enlk.exe
- %TEMP%\myclearsearch-setup.exe
- %PROGRAM_FILES%\MyClearSearch\MyClearSearchSvc.exe -i
- %PROGRAM_FILES%\MyClearSearch\MyClearSearchSvc.exe -r
- %TEMP%\yewknsil.exe
- %TEMP%\brand.exe
- %TEMP%\brand.exe -bkg
- %TEMP%\poqspg.exe
- %TEMP%\dghe.exe
- %TEMP%\sjcwvi.exe
- %TEMP%\yutayi.exe
- %TEMP%\-1998166001
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2529.exe /SP- /suppressmsgboxes /verysilent /noicons /norestart
- %TEMP%\inet.exe c:\Program\Inet2 http://www.qu##ia.com/installer/ 165179 150670 1 1
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2526.exe /SP- /suppressmsgboxes /verysilent /noicons /norestart
- %TEMP%\bpox.exe
- %TEMP%\rvct.exe (загружен из сети Интернет)
- %TEMP%\yewknsil.exe (загружен из сети Интернет)
- %TEMP%\-1998166001 (загружен из сети Интернет)
- %TEMP%\ewihapau.exe (загружен из сети Интернет)
- %TEMP%\sjcwvi.exe (загружен из сети Интернет)
- %TEMP%\enlk.exe (загружен из сети Интернет)
- %TEMP%\bpox.exe (загружен из сети Интернет)
- %TEMP%\poqspg.exe (загружен из сети Интернет)
- %TEMP%\wrnriq.exe (загружен из сети Интернет)
- %TEMP%\dghe.exe (загружен из сети Интернет)
- %TEMP%\yutayi.exe (загружен из сети Интернет)
- %TEMP%\kobf.exe (загружен из сети Интернет)
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- C:\Program\Inet2\inet.exe
- C:\Program\Inet2\settings.cfg_
- C:\Program\Inet2\settings.cfg
- %TEMP%\brand.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sssgtkxxyb[1].php
- %TEMP%\yewknsil.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\mvmnn[1].php
- %TEMP%\wrnriq.exe
- %TEMP%\ewihapau.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\luuttthy[1].php
- C:\Program\Inet2\inetUpServ.exe
- %TEMP%\myclearsearch-setup.exe
- %TEMP%\nsy7.tmp\System.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- %TEMP%\nsy7.tmp\inetc.dll
- %TEMP%\out.html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\post[1].htm
- %TEMP%\stb6.tmp\setup.exe
- %PROGRAM_FILES%\MyClearSearch\MyClearSearchSvc.exe
- %TEMP%\nsw4.tmp
- %PROGRAM_FILES%\MyClearSearch\ShowMsg.exe
- %TEMP%\nsn5.tmp\System.dll
- %PROGRAM_FILES%\MyClearSearch\uninstall.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\opppgguull[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\wsttxkky[1].php
- %TEMP%\dghe.exe
- %TEMP%\yutayi.exe
- %TEMP%\sjcwvi.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\dqqervivmn[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cvwzn[1].php
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2526.exe
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2529.exe
- %TEMP%\inet.exe
- %TEMP%\-1998166001
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rbfsfsg[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\ffffjjx[1].php
- %TEMP%\enlk.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\fppctgu[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\kkxyoccp[1].php
- C:\Program\Inet2\Interop.SHDocVw.dll
- %TEMP%\kobf.exe
- %TEMP%\rvct.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\tgttkyyplp[1].php
- %TEMP%\bpox.exe
- %TEMP%\poqspg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\qzmnre[1].php
- C:\Program\Inet2\inet.dll
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2526.exe
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2529.exe
- %TEMP%\nsn5.tmp\System.dll
- %TEMP%\nsy7.tmp\inetc.dll
- %TEMP%\nsy7.tmp\System.dll
- C:\Temp\91337e03-fc3f-4959-b06c-3e832a2545fc\OfferApp-2529.exe
- <SYSTEM32>\svchost.exe
- %TEMP%\stb6.tmp\setup.exe
- 'up#####.browserseek.com':80
- 'i.###rack.com':80
- 'www.qu##ia.com':80
- 'wp#d':80
- 'aa###nge.com':80
- aa###nge.com/zmjnnaers/mvmnn.php?ad####################################
- www.qu##ia.com/installer/inetUpServ.exe
- aa###nge.com/zmjnnaers/opppgguull.php?ad####################################
- aa###nge.com/zmjnnaers/kkxyoccp.php?ad####################################
- www.qu##ia.com/installer/Interop.SHDocVw.dll
- aa###nge.com/zmjnnaers/sssgtkxxyb.php?ad##################################################################
- up#####.browserseek.com/install.aspx?b=###########
- www.qu##ia.com/installer/inet.exe
- aa###nge.com/zmjnnaers/luuttthy.php?ad####################################
- www.qu##ia.com/installer/settings.cfg
- aa###nge.com/zmjnnaers/wsttxkky.php?ad####################################
- aa###nge.com/zmjnnaers/dqqervivmn.php?ad####################################
- aa###nge.com/zmjnnaers/cvwzn.php?ad####################################
- wp#d/wpad.dat
- aa###nge.com/zmjnnaers/rbfsfsg.php?ad####################################
- aa###nge.com/zmjnnaers/qzmnre.php?ad####################################
- aa###nge.com/zmjnnaers/fppctgu.php?ad####################################
- www.qu##ia.com/installer/inet.dll
- aa###nge.com/zmjnnaers/ffffjjx.php?ad####################################
- aa###nge.com/zmjnnaers/tgttkyyplp.php?ad####################################
- i.###rack.com/post.php
- DNS ASK up#####.browserseek.com
- DNS ASK i.###rack.com
- DNS ASK www.qu##ia.com
- DNS ASK wp#d
- DNS ASK aa###nge.com
- ClassName: 'Shell_TrayWnd' WindowName: ''