Техническая информация
- %PROGRAM_FILES%\Funmoods\1.5.23.22\funmoodssrv.exe /regServer
- %TEMP%\is126078\FunmoodsTB.exe -y -o"%APPDATA%\Mozilla\Firefox\Profiles\CWDGT0~1.DEF\EXTENS~1\ffxtlbr@funmoods.com"
- %TEMP%\nsv2.tmp\tmp0002.exe /S /aflt=softpb /instlRef=softpb /PKL=2 /AL=2
- %TEMP%\nsv2.tmp\ns3.tmp "%TEMP%\nsv2.tmp\lzma.exe" d %TEMP%\nsv2.tmp\inetc.bin %TEMP%\nsv2.tmp\inetc.dll
- %TEMP%\nsv2.tmp\lzma.exe d %TEMP%\nsv2.tmp\inetc.bin %TEMP%\nsv2.tmp\inetc.dll
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\Funmoods\1.5.23.22\escortEng.dll
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\Funmoods\1.5.23.22\escorTlbr.dll
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\Funmoods\1.5.23.22\escortShld.dll
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\Funmoods\1.5.23.22\\bh\escort.dll
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\Funmoods\1.5.23.22\escortApp.dll
- firefox.exe
- iexplore.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul
- <LS_APPDATA>\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage
- <LS_APPDATA>\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage-journal
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- <LS_APPDATA>\funmoods.crx
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\install.rdf
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\chrome.manifest
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iw[1].0&cv=1076&p=240
- %TEMP%\nsv2.tmp\tmp0003.tmp
- %TEMP%\0001EC30.log
- %TEMP%\is126078\payload.cis
- %TEMP%\is126078\payloadflat.cis
- %TEMP%\is126078\escortApp.dll
- %TEMP%\is126078\escortEng.dll
- %TEMP%\is126078\chrome-extension.localstorage
- %TEMP%\is126078\escort.dll
- %PROGRAM_FILES%\is124437.log
- %TEMP%\nsv2.tmp\System.dll
- %TEMP%\nsv2.tmp\Math.dll
- %TEMP%\nsv2.tmp\lzma.exe
- %TEMP%\nsv2.tmp\inetc.bin
- %TEMP%\nsv2.tmp\md5dll.dll
- %TEMP%\nsv2.tmp\inetc.dll
- %TEMP%\nsv2.tmp\tmp0002.exe
- %TEMP%\nsv2.tmp\nsExec.dll
- %TEMP%\nsv2.tmp\ns3.tmp
- %TEMP%\is126078\escorTlbr.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
- %TEMP%\is126078\funmoods-speeddial.crx
- %TEMP%\is126078\funmoods-speeddial_sf.crx
- %TEMP%\is126078\escortShld.dll
- %TEMP%\is126078\favicon.ico
- %TEMP%\is126078\funmoods.crx
- %TEMP%\is126078\Sqlite3.dll
- %TEMP%\is126078\uninstall.exe
- %TEMP%\is126078\funmoodssrv.exe
- %TEMP%\is126078\FunmoodsTB.exe
- <LS_APPDATA>\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage-journal
- %TEMP%\is126078\chrome-extension.localstorage
- %TEMP%\is126078\payloadflat.cis
- %TEMP%\nsv2.tmp\tmp0003.tmp
- %TEMP%\is126078\payload.cis
- %TEMP%\is126078\FunmoodsTB.exe
- %TEMP%\is126078\Sqlite3.dll
- %TEMP%\is126078\funmoods.crx
- %TEMP%\is126078\funmoods-speeddial.crx
- %TEMP%\is126078\funmoods-speeddial_sf.crx
- %TEMP%\nsv2.tmp\tmp0002.exe
- %TEMP%\nsv2.tmp\inetc.bin
- %TEMP%\nsv2.tmp\inetc.dll
- %TEMP%\0001EC30.log
- %TEMP%\nsv2.tmp\ns3.tmp
- %PROGRAM_FILES%\is124437.log
- %TEMP%\nsv2.tmp\nsExec.dll
- %TEMP%\nsv2.tmp\System.dll
- %TEMP%\nsv2.tmp\md5dll.dll
- %TEMP%\nsv2.tmp\lzma.exe
- %TEMP%\nsv2.tmp\Math.dll
- 'rp.###moodscdn.com':80
- 'www.in####lwrapper.com':80
- www.in####lwrapper.com/api/iw/?i=###########################################################
- rp.###moodscdn.com/?pc#############
- DNS ASK rp.###moodscdn.com
- DNS ASK www.in####lwrapper.com
- ClassName: 'Shell_TrayWnd' WindowName: ''