Техническая информация
- %TEMP%\is-5DS41.tmp\Green.tmp /SL5="$1013C,744479,52224,%PROGRAM_FILES%\soft08\Green.exe" /sp- /VERYSILENT /norestart
- %TEMP%\is-UU1JT.tmp\Green.tmp /SL5="$300DA,744479,52224,%PROGRAM_FILES%\soft08\Green.exe"
- %PROGRAM_FILES%\soft08\Green.exe /sp- /VERYSILENT /norestart
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://jy.#144.net/
- %TEMP%\is-KLQBP.tmp\_isetup\_isdecmp.dll
- %TEMP%\is-KLQBP.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-5DS41.tmp\Green.tmp
- %TEMP%\nsh2.tmp\NSISdl.dll
- %PROGRAM_FILES%\soft08\Green.exe
- %PROGRAM_FILES%\soft08\a
- %TEMP%\is-KLQBP.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-UU1JT.tmp\Green.tmp
- %TEMP%\is-KLQBP.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-UU1JT.tmp\Green.tmp
- %TEMP%\is-KLQBP.tmp\_isetup\_isdecmp.dll
- %TEMP%\is-KLQBP.tmp\_isetup\_RegDLL.tmp
- DNS ASK do##.emoney.cn
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''