Техническая информация
- '%PROGRAM_FILES%\tyingyin\setupX_052.exe'
- '%PROGRAM_FILES%\tyingyin\app.exe'
- '%PROGRAM_FILES%\tyingyin\setupX_052.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongjiGateway[1].php
- %TEMP%\nsh3.tmp\reply.htm
- %TEMP%\nsh3.tmp\System.dll
- %TEMP%\nsh3.tmp\inetc.dll
- %TEMP%\nsh3.tmp\NSISdl.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\guanggao[1].htm
- %PROGRAM_FILES%\tyingyin\CKCleaner_silent_t004.exe
- %PROGRAM_FILES%\tyingyin\setupX_052.exe
- %PROGRAM_FILES%\tyingyin\logo.ico
- %HOMEPATH%\Start Menu\Programs\tianplay\tiaplay.lnk
- %TEMP%\nsd2.tmp
- %PROGRAM_FILES%\tyingyin\app.exe
- %HOMEPATH%\Start Menu\Programs\tianplay\Р¶ФШ tiaplay.lnk
- %PROGRAM_FILES%\tyingyin\uninst.exe
- %TEMP%\nsh3.tmp\xID.dll
- %HOMEPATH%\Desktop\tianplay.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\tianplay.lnk
- 'www.zh###suo.com':80
- 'do#####.caiyunstat.com':80
- 'www.sy##zx.com':80
- 'pt.##ujisuo.com':80
- 'localhost':1040
- www.zh###suo.com/guanggao.htm
- do#####.caiyunstat.com/soft/update/24/1.0/CKCleaner_silent_t004.exe
- pt.##ujisuo.com/tongjiGateway.php?id########################################
- www.sy##zx.com/setupX_052.exe
- DNS ASK www.zh###suo.com
- DNS ASK do#####.caiyunstat.com
- DNS ASK pt.##ujisuo.com
- DNS ASK www.sy##zx.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'