Техническая информация
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%ALLUSERSPROFILE%\б╕┐к╩╝б╣▓╦╡е" /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\╠╘▒ж═°.lnk"" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%WINDIR%\" /y /r
- <LS_APPDATA>\zhibo.ICO
- <LS_APPDATA>\Ц±ІҐіµ.lnk
- <LS_APPDATA>\logo.gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\im.qq[1]
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Intrenet Explorer.lnk
- %WINDIR%\Intrenet Explorer.lnk
- <LS_APPDATA>\taobao.ico
- <LS_APPDATA>\ie.ICO
- %TEMP%\~1.bat
- <LS_APPDATA>\889.reg
- <LS_APPDATA>\МФ±¦Нш.lnk
- <LS_APPDATA>\Intrenet Explorer.lnk
- %TEMP%\~1.bat
- 'im.#q.com':80
- 'localhost':1035
- im.#q.com/?12#####
- DNS ASK im.#q.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''