Техническая информация
- '%PROGRAM_FILES%\ttyingyin\setupX_052.exe'
- '%PROGRAM_FILES%\ttyingyin\app.exe'
- '%PROGRAM_FILES%\ttyingyin\setupX_052.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongjiGateway[1].php
- %TEMP%\nsh3.tmp\reply.htm
- %TEMP%\nsh3.tmp\System.dll
- %TEMP%\nsh3.tmp\inetc.dll
- %PROGRAM_FILES%\ttyingyin\setupX_052.exe
- %PROGRAM_FILES%\ttyingyin\Setup_106.exe
- %TEMP%\nsh3.tmp\NSISdl.dll
- %TEMP%\nsh3.tmp\xID.dll
- %PROGRAM_FILES%\ttyingyin\logo.ico
- %HOMEPATH%\Start Menu\Programs\У°Тф\У°Тф.lnk
- %TEMP%\nso2.tmp
- %PROGRAM_FILES%\ttyingyin\app.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\У°Тф.lnk
- %PROGRAM_FILES%\ttyingyin\uninst.exe
- %HOMEPATH%\Start Menu\Programs\У°Тф\Р¶ФШ У°Тф.lnk
- %HOMEPATH%\Desktop\У°Тф.lnk
- <SYSTEM32>\PerfStringBackup.TMP
- 'www.sy##zx.com':80
- 'www.sf##y.net':80
- 'pt.##ujisuo.com':80
- 'localhost':1038
- www.sf##y.net/fh/Setup_106.exe
- www.sy##zx.com/setupX_052.exe
- pt.##ujisuo.com/tongjiGateway.php?id########################################
- DNS ASK do#####.caiyunstat.com
- DNS ASK cd##.866dy.com
- DNS ASK www.sf##y.net
- DNS ASK pt.##ujisuo.com
- DNS ASK www.sy##zx.com
- DNS ASK www.zh###suo.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'