Техническая информация
- '%PROGRAM_FILES%\ffdy\nzos_201042.exe'
- '%PROGRAM_FILES%\ffdy\nzos_201042.exe' (загружен из сети Интернет)
- %PROGRAM_FILES%\ffdy\reply.htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].htm
- %TEMP%\nsn2.tmp\Inetc.dll
- %PROGRAM_FILES%\ffdy\setup_3038.exe
- %PROGRAM_FILES%\ffdy\nzos_201042.exe
- %TEMP%\nsn2.tmp\NSISdl.dll
- %PROGRAM_FILES%\ffdy\·Е·ЕµзУ°.url
- %TEMP%\nsn2.tmp\FindProcDLL.dll
- %TEMP%\nsn2.tmp\System.dll
- %PROGRAM_FILES%\ffdy\uninst.exe
- %HOMEPATH%\Start Menu\Programs\·Е·ЕµзУ°\Uninstall.lnk
- %HOMEPATH%\Start Menu\Programs\·Е·ЕµзУ°\Website.lnk
- 'll#.#czl8.com':80
- 'bb#.#fzzw.com':80
- ll#.#czl8.com/yinyuefm.mdb
- ll#.#czl8.com/niuya.mdb
- bb#.#fzzw.com/index.php
- DNS ASK ll#.#czl8.com
- DNS ASK bb#.#fzzw.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'