Техническая информация
- %ProgramFiles%\1011.txt
- %ProgramFiles%\goodmm.url
- %ProgramFiles%\qq.ico
- %HOMEPATH%\desktop\éïГø´óõâà ↑ê¼.lnk
- %ProgramFiles%\ГҐВ·ГҐГґ.ico
- C:\users\public\desktop\operaa.lnk
- %ProgramFiles%\gg.ico
- %HOMEPATH%\desktop\google fhrome.lnk
- C:\0730.txt
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %ProgramFiles%\qq.ico
- %ProgramFiles%\ГҐВ·ГҐГґ.ico
- %ProgramFiles%\gg.ico
- C:\0730.txt
- 'ji#####.blog.163.com':80
- 'pa#.#aidu.com':80
- 'ji##ezm.com':80
- 'ke##pan.com':80
- 'qq##88.com':80
- http://ji#####.blog.163.com/blog/static/23867405720150319208902/
- http://pa#.#aidu.com/s/1qWPqOlY
- http://www.ji##ezm.com/tj.html
- http://bl##.163.com/login.do?er#####
- http://www.ke##pan.com/space_fenghuo_8061.html
- http://www.qq##88.com/ztj.html?°ж##############
- DNS ASK pa#.#aidu.com
- DNS ASK ji##ezm.com
- DNS ASK ji#####.blog.163.com
- DNS ASK bl##.163.com
- DNS ASK ke##pan.com
- DNS ASK qq##88.com
- ClassName: '' WindowName: 'EXPLOEE.exe'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''