Техническая информация
- %PROGRAM_FILES%\YoudaoDict_zhusha_heima_0112.exe (загружен из сети Интернет) /S
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\dl[1].htm
- %TEMP%\nso2.tmp\nsRandom.dll
- %PROGRAM_FILES%\YoudaoDict_zhusha_heima_0112.exe
- %TEMP%\nso2.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\dl[1].htm
- %TEMP%\nso2.tmp\nsRandom.dll
- %TEMP%\nso2.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\dl[1].htm
- 'dl.##ima8.com':80
- dl.##ima8.com/pv/dl.htm?ad#####################
- DNS ASK dl.##ima8.com
- ClassName: 'Shell_TrayWnd' WindowName: ''