Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Shotcut\qvod_setup.exe' = '%PROGRAM_FILES%\Shotcut\qvod_setup.exe:*:Enabled:LibTerminal4.0'
- %PROGRAM_FILES%\Shotcut\sr.exe http://www.la###angtou.com/u.php?id###
- %PROGRAM_FILES%\Shotcut\qvod_setup.exe
- %ALLUSERSPROFILE%\Desktop\网址导航.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\淘宝打折.lnk
- %ALLUSERSPROFILE%\Desktop\淘宝打折.lnk
- %ALLUSERSPROFILE%\Desktop\免费电影.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\免费电影.lnk
- %ALLUSERSPROFILE%\Desktop\Internet Expleror.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Expleror.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\网址导航.lnk
- %TEMP%\nse3.tmp\nsTools.dll
- %PROGRAM_FILES%\Shotcut\ShotCut.exe
- %PROGRAM_FILES%\Shotcut\qvod_setup.exe
- %TEMP%\nsz2.tmp
- %TEMP%\nse3.tmp\System.dll
- %PROGRAM_FILES%\Shotcut\sr.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\快捷导航\免费电影.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\快捷导航\网址导航.lnk
- %TEMP%\qd5.ini
- %ALLUSERSPROFILE%\Start Menu\Programs\快捷导航\淘宝打折.lnk
- %TEMP%\nse3.tmp\System.dll
- %TEMP%\nse3.tmp\nsTools.dll
- 'www.la###angtou.com':80
- 'qd.##aibo.com':80
- www.la###angtou.com/u.php?id###
- qd.##aibo.com/qd5.jpg
- DNS ASK www.la###angtou.com
- DNS ASK qd.##aibo.com
- ClassName: 'Shell_TrayWnd' WindowName: ''