Техническая информация
- %WINDIR%\update .exe
- %PROGRAM_FILES%\Company\NewProduct\QQxiance.exe
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\aiwod\call.vbe"
- <SYSTEM32>\taskkill.exe /f /im wupdmgr.exe
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\aiwod\file.VBE"
- %PROGRAM_FILES%\aiwod\load.TXT
- %PROGRAM_FILES%\aiwod\listen.TXT
- %PROGRAM_FILES%\aiwod\call.VBE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\99ha[1]
- %PROGRAM_FILES%\aiwod\file.VBE
- %PROGRAM_FILES%\Company\NewProduct\Uninstall.ini
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\Company\NewProduct\QQxiance.exe
- %PROGRAM_FILES%\Company\NewProduct\Uninstall.exe
- %WINDIR%\update .exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'www.99#a.cn':80
- 'localhost':1034
- www.99#a.cn/
- DNS ASK www.99#a.cn
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''