Техническая информация
- <SYSTEM32>\2345_k58347464_movie.exe
- <SYSTEM32>\2345_k58347464_desk.exe
- ClassName: '' WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: '' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass' WindowName: ''
- ClassName: '' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FilemonClass' WindowName: ''
- ClassName: 'pediy06' WindowName: ''
- %APPDATA%\2345.com\2345网址导航.lnk
- %APPDATA%\2345.movie\url.ini
- %HOMEPATH%\Start Menu\2345网址导航.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\2345网址导航.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\影视大全.lnk
- %APPDATA%\2345.movie\影视大全.lnk
- %HOMEPATH%\Desktop\影视大全.lnk
- %HOMEPATH%\Start Menu\影视大全.lnk
- %APPDATA%\2345.com\2345_k58347464_desk.exe
- %APPDATA%\2345.com\url.ini
- <SYSTEM32>\2345_k58347464_desk.exe
- <SYSTEM32>\2345_k58347464_movie.exe
- %HOMEPATH%\Desktop\2345网址导航.lnk
- %APPDATA%\2345.movie\2345_k58347464_movie.exe
- <SYSTEM32>\ncyh3.ini
- <SYSTEM32>\empty.exe
- 'to####.#ianying.2345.com':80
- 'fa###.so88.org':80
- fa###.so88.org/ncyh3/yz.txt
- to####.#ianying.2345.com/index.php
- DNS ASK to####.#ianying.2345.com
- DNS ASK fa###.so88.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '18467-41' WindowName: ''