Техническая информация
- '%PROGRAM_FILES%\yingyin\setupX_052.exe'
- '%PROGRAM_FILES%\yingyin\setupX_052.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongjiGateway[1].php
- %TEMP%\nse3.tmp\inetc.dll
- %TEMP%\nse3.tmp\System.dll
- %TEMP%\nse3.tmp\reply.htm
- %PROGRAM_FILES%\yingyin\CKCleaner_silent_t004.exe
- %PROGRAM_FILES%\yingyin\setupX_052.exe
- %TEMP%\nse3.tmp\NSISdl.dll
- %TEMP%\nse3.tmp\xID.dll
- %HOMEPATH%\Start Menu\Programs\kuУ°Тф\kuУ°Тф.lnk
- %PROGRAM_FILES%\yingyin\logo.ico
- %TEMP%\nss2.tmp
- %HOMEPATH%\Start Menu\Programs\kuУ°Тф\Р¶ФШ kuУ°Тф.lnk
- %PROGRAM_FILES%\yingyin\uninst.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\kuУ°Тф.lnk
- %HOMEPATH%\Desktop\kuУ°Тф.lnk
- 'do#####.caiyunstat.com':80
- 'www.sy##zx.com':80
- 'pt.##ujisuo.com':80
- do#####.caiyunstat.com/soft/update/24/1.0/CKCleaner_silent_t004.exe
- www.sy##zx.com/setupX_052.exe
- pt.##ujisuo.com/tongjiGateway.php?id########################################
- DNS ASK do#####.caiyunstat.com
- DNS ASK www.sy##zx.com
- DNS ASK pt.##ujisuo.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'