Техническая информация
- '%ProgramFiles%\internet explorer\iexplore.exe' "http://www.yxdown.com/count.html"
- %TEMP%\mcc5ee1.tmp
- %APPDATA%\microsoft\windows\privacie\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012023102420231025\index.dat
- %TEMP%\mcc5ee1.tmp
- 'yx##wn.com':80
- 'hm.##idu.com':80
- 'hm.##idu.com':443
- http://www.yx##wn.com/count.html
- http://www.yx##wn.com/static_404/css/nofound.css
- http://www.yx##wn.com/js/jquery.1.9.1.min.js
- http://st####.yxdown.com/js/v.js
- http://re#.#xdown.com/pb.js?t=##########
- http://www.yx##wn.com/static_404/images/404img.png
- http://hm.##idu.com/h.js?da##############################
- http://www.yx##wn.com/favicon.ico
- 'hm.##idu.com':443
- DNS ASK sh####i.yxdown.cn
- DNS ASK yx##wn.com
- DNS ASK st####.yxdown.com
- DNS ASK re#.#xdown.com
- DNS ASK hm.##idu.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles%\internet explorer\iexplore.exe' "http://www.yxdown.com/count.html"' (со скрытым окном)