Техническая информация
- '%TEMP%\RarSFX0\uninstall.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://to###i.1635.cn/tj1/g.asp?ma#############################
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.16#5.cn/ad.html
- %TEMP%\RarSFX0\开心花园之小鬼神偷.exe
- %TEMP%\RarSFX0\update.ini
- %TEMP%\RarSFX0\Update.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\g[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ad[1].html
- %TEMP%\RarSFX0\使用说明.txt
- %TEMP%\RarSFX0\SeedData.xml
- %TEMP%\RarSFX0\chimes.wav
- %TEMP%\RarSFX0\Animal.xml
- %TEMP%\RarSFX0\uninstall.exe
- %TEMP%\RarSFX0\ocr.exe
- %TEMP%\RarSFX0\login.gif
- %TEMP%\RarSFX0\db.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\g[1].asp
- 'localhost':1040
- 'to###i.1635.cn':80
- 'localhost':1037
- 'www.16#5.cn':80
- to###i.1635.cn/tj1/g.asp?ma#############################
- www.16#5.cn/ad.html
- DNS ASK to###i.1635.cn
- DNS ASK www.16#5.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''