Техническая информация
- %WINDIR%\cGuObga\QYHlwR.dll
- %WINDIR%\cGuObga\yAmcMMk.dat
- <SYSTEM32>\RsqZT.dll
- %WINDIR%\GPOlRpo.dll
- <SYSTEM32>\RsqZT.dll
- %WINDIR%\cGuObga\yAmcMMk.dat
- %WINDIR%\GPOlRpo.dll
- 'www.ip##8.com':80
- '<L###LNET>.0.2':80
- 'ip.#atr.cn':80
- 'localhost':1040
- 'www.58##y.com':80
- 'cn##.58ad.cn':80
- 'www.go##0.com':80
- http://www.ip##8.com/
- http:// via <L###LNET>.0.2
- http://ip.#atr.cn/
- http://www.58##y.com/index/getcfg?id######
- http://cn##.58ad.cn/index/getcfg?id######
- http://www.go##0.com/d2/CDClient.dll
- DNS ASK www.ip##8.com
- DNS ASK ip.#atr.cn
- DNS ASK www.go##0.com
- DNS ASK www.58##y.com
- DNS ASK cn##.58ad.cn
- ClassName: 'pop_adv_wnd' WindowName: ''
- ClassName: 'TApplication' WindowName: 'eyoorun'
- ClassName: '' WindowName: 'popadvdlg'
- ClassName: '' WindowName: 'pop_adv_wnd'