Техническая информация
- '%APPDATA%\JjlDownLoader\0CloudEx_onlinesetup.exe' (загружен из сети Интернет)
- '%TEMP%\RarSFX0\youbakinstaller.exe' "http://do####ad.youbak.com/msn/software/partner/1/360Inst-xiannairi.exe"
- '%APPDATA%\JjlDownLoader\0CloudEx_onlinesetup.exe'
- '%TEMP%\RarSFX0\Youbak_MSN_PARTNER2082.exe' /VERYSILENT /SP- /NORESTART
- '%TEMP%\is-S4C1S.tmp\Youbak_MSN_PARTNER2082.tmp' /SL5="$50092,478944,53248,%TEMP%\RarSFX0\Youbak_MSN_PARTNER2082.exe" /VERYSILENT /SP- /NORESTART
- %TEMP%\is-587KG.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\360Inst-xiannairi[1].exe
- %APPDATA%\JjlDownLoader\0CloudEx_onlinesetup.exe
- %TEMP%\is-587KG.tmp\_isetup\_RegDLL.tmp
- %TEMP%\RarSFX0\youbakinstaller.exe
- %TEMP%\RarSFX0\Youbak_MSN_PARTNER2082.exe
- %TEMP%\is-S4C1S.tmp\Youbak_MSN_PARTNER2082.tmp
- %APPDATA%\JjlDownLoader\0CloudEx_onlinesetup.exe
- %TEMP%\RarSFX0\youbakinstaller.exe
- %TEMP%\RarSFX0\Youbak_MSN_PARTNER2082.exe
- %TEMP%\is-587KG.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-587KG.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-S4C1S.tmp\Youbak_MSN_PARTNER2082.tmp
- 'do####ad.youbak.com':80
- 'localhost':1039
- http://do####ad.youbak.com/msn/software/partner/1/360Inst-xiannairi.exe
- DNS ASK do####ad.youbak.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''