Техническая информация
- '%TEMP%\nsf3.tmp\deff_30350.exe'
- '%TEMP%\nsf3.tmp\deff_30350.exe' (загружен из сети Интернет)
- %PROGRAM_FILES%\ffdy\reply.htm
- %TEMP%\nsf3.tmp\Inetc.dll
- %PROGRAM_FILES%\ffdy\uninst.exe
- %TEMP%\nsf3.tmp\setup_3038.exe
- %TEMP%\nsf3.tmp\deff_30350.exe
- %TEMP%\nsf3.tmp\NSISdl.dll
- %TEMP%\nsf3.tmp\FindProcDLL.dll
- %TEMP%\nsf3.tmp\System.dll
- %TEMP%\nsz2.tmp
- %HOMEPATH%\Start Menu\Programs\·Е·ЕµзУ°\Uninstall.lnk
- %HOMEPATH%\Start Menu\Programs\·Е·ЕµзУ°\Website.lnk
- %PROGRAM_FILES%\ffdy\·Е·ЕµзУ°.url
- 'wa##.xkwnz.com':80
- 'go##.xkwnz.com':80
- wa##.xkwnz.com/yinyuefm.txt
- wa##.xkwnz.com/baidushadu.txt
- go##.xkwnz.com/index.php
- DNS ASK wa##.xkwnz.com
- DNS ASK go##.xkwnz.com
- ClassName: 'Shell_TrayWnd' WindowName: ''