Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows MineFilter Diagnostics Service] 'Start' = '00000002'
- <SYSTEM32>\midiasvc.exe /i
- %PROGRAM_FILES%\MineFilter\mineejsvc.exe
- <SYSTEM32>\midiasvc.exe
- <SYSTEM32>\midiasvc.exe /start
- %PROGRAM_FILES%\MineFilter\mineejsvc.ex_ /u
- %PROGRAM_FILES%\MineFilter\mineejsvc.ex_ /stop
- %PROGRAM_FILES%\MineFilter\mineejsvc.exe /start
- %PROGRAM_FILES%\MineFilter\mineejsvc.exe /i
- %PROGRAM_FILES%\MineFilter\mineejsvc.ex_
- %PROGRAM_FILES%\MineFilter\mineejnad.dl_
- %PROGRAM_FILES%\MineFilter\mineej.dl_
- %PROGRAM_FILES%\MineFilter\minerun.ex_
- <LS_APPDATA>\MineFilter\user.ini
- %PROGRAM_FILES%\MineFilter\uninst.exe
- %PROGRAM_FILES%\MineFilter\Log\minefilter_up_20111114.txt
- %TEMP%\nsh2.tmp\System.dll
- %TEMP%\~nsis\c3a005\mineejnad.dll
- %TEMP%\nsh2.tmp\nsProcess.dll
- %TEMP%\nsh2.tmp\splash.jpg
- <SYSTEM32>\midiasvc.ex_
- %TEMP%\nsh2.tmp\newadvsplash.dll
- %TEMP%\nsh2.tmp\System.dll
- %TEMP%\~DF327F.tmp
- %TEMP%\nsh2.tmp\splash.jpg
- %TEMP%\nsh2.tmp\newadvsplash.dll
- %TEMP%\nsh2.tmp\nsProcess.dll
- 'de#####.minefilter.com':80
- de#####.minefilter.com/mine_report.php
- DNS ASK de#####.minefilter.com
- '<IP-адрес в локальной сети>':1035