Техническая информация
- %APPDATA%\GoogleNMore\InstValid.exe -val:[111231][дєєеЅўгЃ®жЎѓжњ€е ‚] 史上最大の淫略
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.Yo##idz.com/ThankYou.aspx?v=#################################### 史上最大の淫略
- <SYSTEM32>\regsvr32.exe "%APPDATA%\GoogleNMore\3.GoogleNMore.dll"
- %APPDATA%\GoogleNMore\FFExt\install.rdf
- %APPDATA%\GoogleNMore\FFExt\chrome.manifest
- %APPDATA%\GoogleNMore\IGoogleNMoreXPCOM.xpt
- %APPDATA%\GoogleNMore\GNMLog.txt
- %APPDATA%\GoogleNMore\FFExt\chrome\content\googlenmore.xul
- %APPDATA%\GoogleNMore\FFExt\chrome\content\googlenmore.js
- %APPDATA%\GoogleNMore\GoogleNMoreXPCOM.dll
- %APPDATA%\GoogleNMore\GoogleNMoreLicense32.txt
- %APPDATA%\GoogleNMore\Uninstall.bat
- %APPDATA%\GoogleNMore\MFC42U.DLL
- %APPDATA%\GoogleNMore\InstValid.exe
- %APPDATA%\GoogleNMore\3.GoogleNMore.dll
- %APPDATA%\GoogleNMore\GoogleNMore.ini
- 'www.yo##idz.com':80
- 'localhost':1037
- www.yo##idz.com/SrvConfig11.aspx?My#########
- www.yo##idz.com/download11/VerInfo11.txt?My#########
- DNS ASK www.yo##idz.com
- '<IP-адрес в локальной сети>':1036
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''