Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IEXPIORE.exe' = '%TEMP%\IEXPIORE.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<Drive name for removable media>:\FlySoft\micsoft.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\StormService] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\mfc43] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\krnlhelp] 'Start' = '00000002'
- %WINDIR%\mfc43.exe
- %TEMP%\starm.exe
- %WINDIR%\sacssmor\Thunder5.exe
- %TEMP%\internet.exe
- %WINDIR%\system\lass32.exe
- %PROGRAM_FILES%\MSBuild\qsrtsvxw.exe lnk nothing
- <SYSTEM32>\internet.exe
- %PROGRAM_FILES%\Internet Explorer\Funshon.exe
- <SYSTEM32>\krnlhelp.exe
- %TEMP%\small.exe
- %TEMP%\GoogleTools.exe
- %TEMP%\conome.exe
- %TEMP%\IExplorer.exe
- <SYSTEM32>\micsoft.exe
- %TEMP%\IEXPIORE.exe
- %TEMP%\VStart.exe
- %TEMP%\fdoud01.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.pp##pp.cn/fd/data/user.asp?us################################################################
- <SYSTEM32>\net1.exe stop sharedaccess
- <SYSTEM32>\at.exe /delete /yes
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.ku##5.com/#27062
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.51##b.com
- <SYSTEM32>\cmd.exe /c afc9fe2f418b00a0.bat
- <SYSTEM32>\rundll32.exe fly100.dll , InstallMyDll
- <SYSTEM32>\cmd.exe /c %WINDIR%\system\75.90884.bat
- <SYSTEM32>\ping.exe 127.1
- <SYSTEM32>\net.exe stop sharedaccess
- <SYSTEM32>\svchost.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %HOMEPATH%\Start Menu\Internet Explorer.lnk
- <SYSTEM32>\urlmor.dll
- %PROGRAM_FILES%\MSBuild\qsrtsvxw.exe
- %PROGRAM_FILES%\Internet Explorer\Funshon.exe
- %PROGRAM_FILES%\Internet Explorer\3.ho
- %PROGRAM_FILES%\Internet Explorer\1.ho
- %WINDIR%\system\lass32.exe
- %ALLUSERSPROFILE%\Start Menu\Internet Explorer.lnk
- <SYSTEM32>\Web.ini
- %HOMEPATH%\Desktop\7k7kРЎУОП·.lnk
- %WINDIR%\WinBaDaoSe.ini
- %WINDIR%\WinAdmin.ini
- %HOMEPATH%\Favorites\РЎУОП·,ФЪПЯРЎУОП·,Л«ИЛРЎУОП·,7k7kРЎУОП·.url
- %ALLUSERSPROFILE%\Start Menu\Programs\Internet Explorer.lnk
- %HOMEPATH%\Start Menu\Programs\Internet Explorer.lnk
- %HOMEPATH%\Favorites\їб256НшЦ·ґуИ«--ВМЙ«НшЦ·--ЦР№ъЧоЧЁТµµДНшЦ·µјєЅ.url
- %HOMEPATH%\Favorites\ґґТµЧКС¶јУГЛЈ[ґґТµЧКС¶-ЦР№ъґґТµГЕ»§НшХѕ].url
- %WINDIR%\system\75.90884.bat
- <SYSTEM32>\fly100.dll
- %TEMP%\VStart.exe
- %TEMP%\IEXPIORE.exe
- <SYSTEM32>\dllcache\fly100.dll
- %TEMP%\conome.exe
- %TEMP%\GoogleTools.exe
- %TEMP%\IExplorer.exe
- %TEMP%\small.exe
- %TEMP%\fdoud01.exe
- <SYSTEM32>\micsoft.exe
- %WINDIR%\mfc43.exe
- %TEMP%\starm.exe
- %TEMP%\3596799a1543bc9f.aqq
- <SYSTEM32>\internet.exe
- %TEMP%\afc9fe2f418b00a0.bat
- %WINDIR%\sacssmor\Thunder5.exe
- <SYSTEM32>\krnlhelp.exe
- %TEMP%\internet.exe
- %PROGRAM_FILES%\MSBuild\qsrtsvxw.exe
- %TEMP%\IEXPIORE.exe
- <SYSTEM32>\internet.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %HOMEPATH%\Start Menu\Internet Explorer.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Internet Explorer.lnk
- %ALLUSERSPROFILE%\Start Menu\Internet Explorer.lnk
- %HOMEPATH%\Desktop\7k7kРЎУОП·.lnk
- %TEMP%\small.exe
- %TEMP%\3596799a1543bc9f.aqq
- %TEMP%\~DFD13E.tmp
- %TEMP%\internet.exe
- %TEMP%\starm.exe
- 'localhost':1071
- 'localhost':1056
- 'ha####qlf.3322.org':8888
- 'localhost':1089
- 'localhost':1076
- 'localhost':1074
- 'localhost':1053
- 'ad.##595.com':80
- 'bb#.#x008.cn':80
- 'localhost':8389
- 'localhost':1048
- 'localhost':1047
- '25#.#55.255.255':8888
- ad.##595.com/count/count.asp?sz####################################################################################################################################################################################################
- bb#.#x008.cn/ip.txt
- DNS ASK www.51##b.com
- DNS ASK rn######.##m.cn&mac=00-00-00-00-00-01
- DNS ASK co####.hao123soso.cn
- DNS ASK www.k-#c.cn
- DNS ASK www.ku##5.com
- DNS ASK www.pp##pp.cn
- DNS ASK ad.##595.com
- DNS ASK bb#.#x008.cn
- DNS ASK ha####qlf.3322.org
- DNS ASK 10###6.3322.org
- DNS ASK pa#####.funshion.com
- ClassName: '' WindowName: ''
- ClassName: 'funshion_player_tzdenjohn' WindowName: '?????? V1.5.3.8Beta'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: '???? - ???,??? - Microsoft Internet Explorer'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'ToolbarWindow32' WindowName: ''
- ClassName: 'MSTaskSwWClass' WindowName: ''