Техническая информация
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\regini.exe' "%TEMP%\255937.ini"
- %TEMP%\255937.ini
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\255937.ini
- 'do##.#z-guogeng.com':80
- 'wm.###guogeng.com':80
- 'do##.dtddn.com':80
- 'lo#.#tddn.com':80
- 'dl###1.qq.com':80
- wm.###guogeng.com/wm3000/2065.rar
- wm.###guogeng.com/wm3000/9732.rar
- wm.###guogeng.com/wm3000/33.rar
- wm.###guogeng.com/wm3000/6779.rar
- wm.###guogeng.com/wm3000/9985.rar
- wm.###guogeng.com/wm3000/3231.rar
- wm.###guogeng.com/wm3000/2938.rar
- wm.###guogeng.com/wm3000/3250.rar
- dl###1.qq.com/invc/tt/QQBrowser_Setup_ExternalForum_15649.exe
- lo#.#tddn.com/UpLog/worklog.asp?Na#############################################
- lo#.#tddn.com/UpLog/worklog.asp?Na##############################################
- do##.dtddn.com/74.rar
- wm.###guogeng.com/wm3000/9467.rar
- lo#.#tddn.com/UpLog/worklog.asp?Na###################################################
- do##.#z-guogeng.com/74.rar
- DNS ASK do##.#z-guogeng.com
- DNS ASK wm.###guogeng.com
- DNS ASK do##.dtddn.com
- DNS ASK lo#.#tddn.com
- DNS ASK dl###1.qq.com