Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GreeDou' = '%PROGRAM_FILES%\douzi\greendou.exe'
- '<SYSTEM32>\DllHost.exe' /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\¶№ЧУ\¶№ЧУ.lnk
- %HOMEPATH%\Desktop\¶№ЧУ.lnk
- %PROGRAM_FILES%\douzi\license.txt
- %TEMP%\nsoCC.tmp\NSISdl.dll
- %TEMP%\nsoCC.tmp\tian.ini.log
- %TEMP%\nsoCC.tmp\tian.ini.log
- %TEMP%\nsoCC.tmp\NSISdl.dll
- 'fw.#d33.org':80
- 'wt#.#xsx.org':88
- fw.#d33.org/setup/?na######################################
- DNS ASK fw.#d33.org
- DNS ASK dn#.##ftncsi.com
- DNS ASK wt#.#xsx.org