Техническая информация
- <Текущая директория>\jiangyiguosharuanziqidong.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows_smss.scr.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows_dwm.scr.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\adb.url
- [<HKLM>\System\CurrentControlSet\Services\Spooler11] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Spooler11] 'ImagePath' = '%WINDIR%\sdqlyk~1\EEEEEEEEEEEEEEEEEE'
- 'Spooler11' %WINDIR%\sdqlyk~1\eeeeeeeeeeeeeeeeee
- C:\yyy123
- <Текущая директория>\jiangyiguosharuanziqidong.lnk
- %WINDIR%\sdqlyk~1\eeeeeeeeeeeeeeeeee
- %TEMP%\10ed3b.tmp
- C:\yyy123
- %TEMP%\10ed3b.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\adb.url
- <Полный путь к файлу>
- 'r.###ne.qq.com':80
- 'r.###ne.qq.com':443
- 'cr#.##gicert-cn.com':80
- 'oc##.dcocsp.cn':80
- 'microsoft.com':80
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHv1Dj%2BciPJEWH5JNtwL5Y07mRqwQUxBF%2BiECGwkG%2FZfMa4bRTQKOr7H0CEArIzKqFYmE3jrS4gQrE3QI%3D
- DNS ASK r.###ne.qq.com
- DNS ASK cr#.##gicert-cn.com
- DNS ASK oc##.dcocsp.cn
- DNS ASK microsoft.com