Техническая информация
- '%TEMP%\nse3.tmp\play_2051_143725.exe' /s
- '%PROGRAM_FILES%\ttyingyin\app.exe'
- '%TEMP%\nse3.tmp\play_2051_143725.exe' (загружен из сети Интернет)
- %TEMP%\nse3.tmp\reply.htm
- %TEMP%\nse3.tmp\NSISdl.dll
- %TEMP%\nse3.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongjiGateway[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\guanggao[1].htm
- %TEMP%\nse3.tmp\setupX_052.exe
- %TEMP%\nse3.tmp\play_2051_143725.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\fengyun[1].html
- %PROGRAM_FILES%\ttyingyin\logo.ico
- %HOMEPATH%\Start Menu\Programs\МмМмУ°Тф\МмМмУ°Тф.lnk
- %TEMP%\nsg2.tmp
- %PROGRAM_FILES%\ttyingyin\app.exe
- %HOMEPATH%\Desktop\МмМмУ°Тф.lnk
- %TEMP%\nse3.tmp\xID.dll
- %TEMP%\nse3.tmp\System.dll
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МмМмУ°Тф.lnk
- %PROGRAM_FILES%\ttyingyin\uninst.exe
- 'www.ht##f.com':80
- 'do####ad.yykc.com':81
- 'www.sy##zx.com':80
- 'ch####hi.32so.com':80
- 'localhost':1035
- 'cd#.#66dy.com':80
- www.ht##f.com/guanggao.htm
- www.sy##zx.com/setupX_052.exe
- www.ht##f.com/fengyun.html
- ch####hi.32so.com/tongjiGateway.php?id########################################
- cd#.#66dy.com/play_2051_143725.exe
- DNS ASK do####ad.yykc.com
- DNS ASK www.sy##zx.com
- DNS ASK www.ht##f.com
- DNS ASK ch####hi.32so.com
- DNS ASK cd#.#66dy.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'