Техническая информация
- '<LS_APPDATA>\wauee_jx029.exeex.exe' <LS_APPDATA>\wauee_jx029.exe2014888http://do##.jdrili.com/wauee_jx029.exe?37######
- '<LS_APPDATA>\365weatherIns_184.exeex.exe' <LS_APPDATA>\365weatherIns_184.exe2014888http://lm.##ilequ.com/update/365/365weatherIns_184.exe?77###################
- '<LS_APPDATA>\-8388_158004_mn.exeex.exe' <LS_APPDATA>\-8388_158004_mn.exe2014888http://ff###.qiniudn.com/-8388_158004_mn.exe?37######
- '<LS_APPDATA>\114gglm_007.exeex.exe' <LS_APPDATA>\114gglm_007.exe2014888http://wu##.#####n-hangzhou.aliyuncs.com/qd/114gglm_007.exe?37######
- '<LS_APPDATA>\setup_qd262.exeex.exe' <LS_APPDATA>\setup_qd262.exe2014888http://ff###.qiniudn.com/setup_qd262.exe?37######
- '<LS_APPDATA>\setup_open_338.exeex.exe' <LS_APPDATA>\setup_open_338.exe2014888http://do####ad.wuji.com/wuji/open/setup_open_338.exe?qq######################
- '<LS_APPDATA>\setup_qd262.exe'
- '<LS_APPDATA>\Setup_027.exe'
- '<LS_APPDATA>\-8388_158004_mn.exe'
- '<LS_APPDATA>\play_3020_161213.exeex.exe' <LS_APPDATA>\play_3020_161213.exe2014888http://www.hu####-global.com/play_3020_161213.exe?37######
- '<LS_APPDATA>\gaevnx_70500.exe'
- '<LS_APPDATA>\kuping_s_51630.exeex.exe' <LS_APPDATA>\kuping_s_51630.exe2014888http://do####ad.wallba.com/download.php/kuping_s_51630.exe?37######
- '<LS_APPDATA>\fgcn_101520.exeex.exe' <LS_APPDATA>\fgcn_101520.exe2014888http://do###.flashget.com/un/fgcn_101520.exe?37##########
- '<LS_APPDATA>\Setup_027.exeex.exe' <LS_APPDATA>\Setup_027.exe2014888http://www.sf##y.net/tdj/Setup_027.exe
- '%TEMP%\RarSFX0\114lm_rebo_17645.exe'
- '<LS_APPDATA>\gaevnx_70500.exeex.exe' <LS_APPDATA>\gaevnx_70500.exe2014888http://ff###.qiniudn.com/cpexym_70500.exe?37####################
- '<LS_APPDATA>\SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exeex.exe' <LS_APPDATA>\SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exe2014888http://so#####gyin.t3nlink.com/link/157294/?16#######################
- '<LS_APPDATA>\doyo_3052_s.exeex.exe' <LS_APPDATA>\doyo_3052_s.exe2014888http://so##.doyo.cn/soft/doyo_3052_s.exe?37######
- '<LS_APPDATA>\NmnPps_1088.exeex.exe' <LS_APPDATA>\NmnPps_1088.exe2014888http://do##.u5c.net/nmnpps_1088.exe?37######
- '<LS_APPDATA>\setups89800.exeex.exe' <LS_APPDATA>\setups89800.exe2014888http://dl.##andiyd.com/dl/setups89800.exe?78################
- '<LS_APPDATA>\setup_ad7154.exeex.exe' <LS_APPDATA>\setup_ad7154.exe2014888http://do##.##aoxinrili.com/hezi/jm/setup_ad7154.exe?37######
- '<LS_APPDATA>\play_2098.exeex.exe' <LS_APPDATA>\play_2098.exe2014888http://ma#.#zgzs.com/down/down/get.asp?na#########################
- '<LS_APPDATA>\Setup_027.exe' (загружен из сети Интернет)
- '<LS_APPDATA>\setup_qd262.exe' (загружен из сети Интернет)
- '<LS_APPDATA>\gaevnx_70500.exe' (загружен из сети Интернет)
- '<LS_APPDATA>\-8388_158004_mn.exe' (загружен из сети Интернет)
- '<SYSTEM32>\taskkill.exe' /F /IM SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM 114gglm_007.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM 365weatherIns_184.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM fgcn_101520.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\wauee_jx029.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\NmnPps_1088.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM kuping_s_51630.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\Setup_027.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM setup_open_338.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM setup_ad7154.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM play_2098.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM Setup_027.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM doyo_3052_s.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM wauee_jx029.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM play_3020_161213.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM NmnPps_1088.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM setups89800.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM setup_qd262.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM -8388_158004_mn.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\kuping_s_51630.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM gaevnx_70500.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\gaevnx_70500.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setup_qd262.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\-8388_158004_mn.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\fgcn_101520.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setups89800.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\play_2098.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\doyo_3052_s.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\365weatherIns_184.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\play_3020_161213.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\114gglm_007.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setup_open_338.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setup_ad7154.exeex.exe.bat"
- <LS_APPDATA>\365weatherIns_184.exeex.exe
- <LS_APPDATA>\wauee_jx029.exeex.exe
- <LS_APPDATA>\play_3020_161213.exeex.exe
- <LS_APPDATA>\setup_open_338.exeex.exe
- <LS_APPDATA>\114gglm_007.exeex.exe
- <LS_APPDATA>\NmnPps_1088.exeex.exe
- <LS_APPDATA>\-8388_158004_mn.exeex.exe
- <LS_APPDATA>\setup_qd262.exeex.exe
- <LS_APPDATA>\setup_qd262.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\setup_qd262[1]
- <LS_APPDATA>\Setup_027.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\Setup_027[1].exe
- <LS_APPDATA>\gaevnx_70500.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cpexym_70500[1].exe
- <LS_APPDATA>\-8388_158004_mn.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\-8388_158004_mn[1]
- %TEMP%\RarSFX0\pla2y_3022_17645.exe
- %TEMP%\RarSFX0\Pdlay_2059_17645.exe
- <LS_APPDATA>\gaevnx_70500.exeex.exe
- %PROGRAM_FILES%\jq\open.ini
- %TEMP%\RarSFX0\IFo32xInstall-y-c206554920-s-nsi-tp-x.exe
- %TEMP%\RarSFX0\setup_238_54920(2431).exe
- %TEMP%\RarSFX0\88817645.exe
- %TEMP%\RarSFX0\114lm_rebo_17645.exe
- <LS_APPDATA>\play_2098.exeex.exe
- <LS_APPDATA>\setup_ad7154.exeex.exe
- <LS_APPDATA>\setups89800.exeex.exe
- <LS_APPDATA>\doyo_3052_s.exeex.exe
- <LS_APPDATA>\kuping_s_51630.exeex.exe
- <LS_APPDATA>\Setup_027.exeex.exe
- <LS_APPDATA>\SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exeex.exe
- <LS_APPDATA>\fgcn_101520.exeex.exe
- <LS_APPDATA>\365weatherIns_184.exeex.exe
- <LS_APPDATA>\wauee_jx029.exeex.exe
- <LS_APPDATA>\setup_ad7154.exeex.exe
- <LS_APPDATA>\setup_open_338.exeex.exe
- <LS_APPDATA>\NmnPps_1088.exeex.exe
- <LS_APPDATA>\doyo_3052_s.exeex.exe
- <LS_APPDATA>\Setup_027.exeex.exe
- <LS_APPDATA>\setups89800.exeex.exe
- <LS_APPDATA>\play_2098.exeex.exe
- <LS_APPDATA>\-8388_158004_mn.exeex.exe
- <LS_APPDATA>\gaevnx_70500.exeex.exe
- %PROGRAM_FILES%\jq\open.ini
- <LS_APPDATA>\setup_qd262.exeex.exe
- <LS_APPDATA>\114gglm_007.exeex.exe
- <LS_APPDATA>\SoHuVA_4.2.0.88-c203949282-run-s-bwd-bgg-x.exeex.exe
- <LS_APPDATA>\play_3020_161213.exeex.exe
- <LS_APPDATA>\kuping_s_51630.exeex.exe
- <LS_APPDATA>\fgcn_101520.exeex.exe
- 'www.sf##y.net':80
- 'ff###.qiniudn.com':80
- 'cl####.jxdcw.com':80
- ff###.qiniudn.com/setup_qd262.exe?37######
- www.sf##y.net/tdj/Setup_027.exe
- ff###.qiniudn.com/-8388_158004_mn.exe?37######
- cl####.jxdcw.com/tongji.asp?sn#######################################
- ff###.qiniudn.com/cpexym_70500.exe?37####################
- DNS ASK do##.##aoxinrili.com
- DNS ASK lm.##ilequ.com
- DNS ASK dl.##andiyd.com
- DNS ASK www.hu####-global.com
- DNS ASK do##.u5c.net
- DNS ASK do####ad.wuji.com
- DNS ASK do##.jdrili.com
- DNS ASK so##.doyo.cn
- DNS ASK www.sf##y.net
- DNS ASK do###.flashget.com
- DNS ASK cl####.jxdcw.com
- DNS ASK ff###.qiniudn.com
- DNS ASK wu##.#####n-hangzhou.aliyuncs.com
- DNS ASK ma#.#zgzs.com
- DNS ASK so#####gyin.t3nlink.com
- DNS ASK do####ad.wallba.com
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'