Техническая информация
- %WINDIR%\regedit.exe /s <LS_APPDATA>\889.reg
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\╠╘▒ж═°.lnk" "%ALLUSERSPROFILE%\╫└├ц\" /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\Intrenet Explorer.lnk" "%ALLUSERSPROFILE%\б╕┐к╩╝б╣▓╦╡е" /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\Intrenet Explorer.lnk" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\Intrenet Explorer.lnk" "%WINDIR%\" /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\taobao.ico" "%WINDIR%\" /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\Intrenet Explorer.lnk" "%ALLUSERSPROFILE%\╫└├ц\" /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\╠╘▒ж═°.lnk" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe "<LS_APPDATA>\ie.ico" "%WINDIR%\" /y /r
- %WINDIR%\ie.ICO
- %WINDIR%\taobao.ico
- %ALLUSERSPROFILE%\╫└├ц\Intrenet Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Intrenet Explorer.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\im.qq[1]
- %WINDIR%\Intrenet Explorer.lnk
- <LS_APPDATA>\logo.gif
- <LS_APPDATA>\taobao.ico
- <LS_APPDATA>\ie.ICO
- %TEMP%\~1.bat
- <LS_APPDATA>\889.reg
- <LS_APPDATA>\МФ±¦Нш.lnk
- <LS_APPDATA>\Intrenet Explorer.lnk
- %TEMP%\~1.bat
- 'im.#q.com':80
- 'localhost':1036
- im.#q.com/
- DNS ASK im.#q.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''