Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\QQ.exe.lnk
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.ke##m.info/?tu####
- %TEMP%\is-SPPIT.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-7MLD7.tmp\setup_qvod.tmp
- %TEMP%\is-SPPIT.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\keaim[1]
- %TEMP%\Temp\config.ini
- %TEMP%\Temp\QQ.exe
- %TEMP%\Temp\2.exe
- %TEMP%\Temp\1.exe
- %TEMP%\Temp\setup_qvod.exe
- %TEMP%\Temp\tuitan.exe
- %TEMP%\Temp\vmcsch32.exe
- 'www.ke##m.info':80
- 'ce###.10642.com':80
- 'localhost':1035
- www.ke##m.info/?tu####
- ce###.10642.com/197574_IP.txt
- DNS ASK www.ke##m.info
- DNS ASK ce###.10642.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''