Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonZoneCrossing' = '00000000'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnPostRedirect' = '00000000'
- %TEMP%\nsa562b.tmp
- %TEMP%\nsq563c.tmp\system.dll
- %APPDATA%\2345\lycq\lander.ini
- %TEMP%\nsq563c.tmp\findprocdll.dll
- %APPDATA%\2345\lycq\lycq.exe
- %APPDATA%\2345\lycq\uninst.exe
- %HOMEPATH%\desktop\à ¶ôâ´«ææ.lnk
- %APPDATA%\microsoft\windows\start menu\programs\2345óîï·öððä\à ¶ôâ´«ææ\à ¶ôâ´«ææ.lnk
- %APPDATA%\microsoft\windows\start menu\programs\2345óîï·öððä\à ¶ôâ´«ææ\ð¶ôøà ¶ôâ´«ææ.lnk
- %TEMP%\installstat.tmp
- %TEMP%\nsq563c.tmp\findprocdll.dll
- %TEMP%\nsq563c.tmp\system.dll
- 'g.###.2345.com':80
- 'g.###.2345.com':443
- 'oc##.##ctigochina.com':80
- http://g.###.2345.com/ps.gif?id##########################################################################################################################################################
- http://oc##.##ctigochina.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRVphVa8zQh6Zxn0hISd66zlb70OAQUxlReWmSYhsP71A9IiStbK%2FOxIK8CEEBq2HZT%2Bsl8u%2B02Frrjmc8%3D
- 'g.###.2345.com':443
- DNS ASK g.###.2345.com
- DNS ASK oc##.##ctigochina.com
- '%APPDATA%\2345\lycq\lycq.exe' /setupsucc