Technical Information
- '%TEMP%\nsh3.tmp\setup1146568.exe'
- '%TEMP%\nsh3.tmp\mkcf_70032.exe'
- '%TEMP%\nsh3.tmp\setup_qd318.exe'
- '%TEMP%\nsh3.tmp\setup_3038.exe'
- '%TEMP%\nsh3.tmp\kuping_s_51022.exe'
- '%TEMP%\nsh3.tmp\setup_open_3747.exe'
- '%TEMP%\nsh3.tmp\s2222.exe'
- '%TEMP%\nsh3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe'
- '%TEMP%\nsh3.tmp\dianxin_silent[108].exe'
- '%TEMP%\nsh3.tmp\pczh_155.exe'
- '%TEMP%\nsh3.tmp\90018_ailiao.exe'
- '%TEMP%\nsh3.tmp\izrhfo_30071.exe'
- '%TEMP%\nsh3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\setup_3038.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\setup_qd318.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\kuping_s_51022.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\90018_ailiao.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\izrhfo_30071.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\pczh_155.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\dianxin_silent[108].exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\s2222.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\setup_open_3747.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\mkcf_70032.exe' (downloaded from the Internet)
- '%TEMP%\nsh3.tmp\setup1146568.exe' (downloaded from the Internet)
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\wuji[1].txt
- %TEMP%\nsh3.tmp\setup_open_3747.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kuping[1].txt
- %TEMP%\nsh3.tmp\s2222.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ruixing[1].txt
- %TEMP%\nsh3.tmp\setup1146568.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\xiaoxinrili[1].txt
- %TEMP%\nsh3.tmp\kuping_s_51022.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\souhu[1].txt
- %TEMP%\nsh3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe
- %TEMP%\nsh3.tmp\SelfDel.dll
- %TEMP%\nsh3.tmp\setup_qd318.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\yinyuefm[1].txt
- %TEMP%\nsh3.tmp\setup_3038.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\guangsu[1].txt
- %TEMP%\nsh3.tmp\Inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zhihui[1].txt
- %TEMP%\nsh3.tmp\pczh_155.exe
- %PROGRAM_FILES%\ffdymovie\uninst.exe
- %TEMP%\nsc2.tmp
- %TEMP%\nsh3.tmp\FindProcDLL.dll
- %HOMEPATH%\Start Menu\Programs\ffdymovie\Uninstall.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\dianxin[1].txt
- %TEMP%\nsh3.tmp\izrhfo_30071.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\baiduweishi[1].txt
- %TEMP%\nsh3.tmp\mkcf_70032.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\baidushadu[1].txt
- %TEMP%\nsh3.tmp\dianxin_silent[108].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\ailiao[1].txt
- %TEMP%\nsh3.tmp\90018_ailiao.exe
- %TEMP%\nsh3.tmp\setup1146568.exe
- %TEMP%\nsh3.tmp\SelfDel.dll
- %TEMP%\nsh3.tmp\s2222.exe
- %TEMP%\nsh3.tmp\setup_3038.exe
- %TEMP%\nsh3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe
- %TEMP%\nsh3.tmp\setup_qd318.exe
- %TEMP%\nsh3.tmp\setup_open_3747.exe
- %TEMP%\nsh3.tmp\pczh_155.exe
- %TEMP%\nsh3.tmp\FindProcDLL.dll
- %TEMP%\nsh3.tmp\dianxin_silent[108].exe
- %TEMP%\nsh3.tmp\90018_ailiao.exe
- %TEMP%\nsh3.tmp\Inetc.dll
- %TEMP%\nsh3.tmp\mkcf_70032.exe
- %TEMP%\nsh3.tmp\kuping_s_51022.exe
- %TEMP%\nsh3.tmp\izrhfo_30071.exe
- 'pu########.#28ceb8923f4f.d01.nanoyun.com':80
- pu########.#28ceb8923f4f.d01.nanoyun.com/kuping.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/wuji.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/xiaoxinrili.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/souhu.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/guangsu.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/yinyuefm.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/ailiao.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/dianxin.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/zhihui.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/ruixing.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/baiduweishi.txt
- pu########.#28ceb8923f4f.d01.nanoyun.com/baidushadu.txt
- DNS ASK pu########.#28ceb8923f4f.d01.nanoyun.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'