Technical Information
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsxde10.tmp\findprocdll.dll
- %TEMP%\nsxde10.tmp\inetc.dll
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\ffdymovie\uninstall.lnk
- %ProgramFiles(x86)%\ffdymovie\uninst.exe
- %TEMP%\nsxde10.tmp\system.dll
- %TEMP%\nsxde10.tmp\selfdel.dll
- %TEMP%\nsxde10.tmp\findprocdll.dll
- %TEMP%\nsxde10.tmp\inetc.dll
- %TEMP%\nsxde10.tmp\selfdel.dll
- %TEMP%\nsxde10.tmp\system.dll
- 'localhost':80
- 'al#######.#ss-cn-hangzhou.aliyuncs.com':80
- http://al#######.#ss-cn-hangzhou.aliyuncs.com/other.txt
- DNS ASK pc#####.b0.upaiyun.com
- DNS ASK al#######.#ss-cn-hangzhou.aliyuncs.com
- DNS ASK to####.lssen.com
- '%WINDIR%\syswow64\explorer.exe'