Техническая информация
- '%PROGRAM_FILES%\Yesform\Freedown\freeDown.exe'
- '%PROGRAM_FILES%\Yesform\Freedown\freeDown.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\update_chg[1].exe
- %PROGRAM_FILES%\Yesform\Freedown\freeDown.exe
- %PROGRAM_FILES%\Yesform\Freedown\update\update_chg.exe
- %PROGRAM_FILES%\Yesform\Freedown\update_chk.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update_chk[1].exe
- %PROGRAM_FILES%\Yesform\Freedown\update.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\freeDown[1].ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\freeDown[1].exe
- %PROGRAM_FILES%\Yesform\Freedown\freeDown.ico
- 'www.ye##orm.com':80
- www.ye##orm.com/freeform/search/update/update_chg.exe
- www.ye##orm.com/freeform/search/update/update_chk.exe
- www.ye##orm.com/freeform/search/update/freeDown.exe
- www.ye##orm.com/freeform/search/update/update.ini
- www.ye##orm.com/freeform/search/update/freeDown.ico
- DNS ASK www.ye##orm.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'