Техническая информация
- %TEMP%\nsec783.tmp\system.dll
- %TEMP%\setup.exe
- %TEMP%\theworld_3.0_2.exe
- %TEMP%\max2_133daohang4.exe
- %HOMEPATH%\favorites\====Гøö·ö®¼ò====.url
- %TEMP%\nsze714.tmp
- %TEMP%\nspe725.tmp\êà ½çö®´°a.ini
- %TEMP%\nsue743.tmp
- %TEMP%\nspe773.tmp\inetload2.dll
- %TEMP%\nspe725.tmp\iospecial.ini
- %TEMP%\nspe725.tmp\modern-wizard.bmp
- %ProgramFiles(x86)%\internet explorer\newiexplore.exe
- C:\launch internet explorer browser.lnk
- %WINDIR%\sppert.ini
- %TEMP%\deltemp.bat
- %TEMP%\nsec783.tmp\system.dll
- C:\launch internet explorer browser.lnk
- %TEMP%\nspe773.tmp\inetload2.dll
- %TEMP%\setup.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- 'mk.##xthon.cn':80
- http://mk.##xthon.cn/online_inst/data.ini
- http://mk.##xthon.cn/133daohang4/setup_133daohang4.exe
- DNS ASK mk.##xthon.cn
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\setup.exe'
- '%TEMP%\theworld_3.0_2.exe'
- '%TEMP%\max2_133daohang4.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\DelTemp.bat" " (со скрытым окном)