Technical Information
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://61.##4.62.83:1111/down.php?union=yitian&agent=0
- %TEMP%\nsua821.tmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\5xif854a\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\dxy10gu6\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\552vtdm0\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\3wsv15m0\desktop.ini
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\down[1]
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012025020920250210\index.dat
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\╞⌠╢В» internet explorer σВ»└└╞≈.lnk
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\internet explorer.lnk
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\errorpagetemplate[1]
- %TEMP%\nsua822.tmp\banner.dll
- %WINDIR%\syswow64\bbplay\bb.exe
- %HOMEPATH%\desktop\В№ГєГâó°ôº.lnk
- %APPDATA%\microsoft\windows\start menu\В№ГєГâó°ôº.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\В№ГєГâó°ôº.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\В№ГєГâó°ôº.lnk
- %HOMEPATH%\desktop\èëìåòõêõð´õæ.lnk
- %APPDATA%\microsoft\windows\start menu\èëìåòõêõð´õæ.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\èëìåòõêõð´õæ.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\èëìåòõêõð´õæ.lnk
- %WINDIR%\syswow64\bbplayer.exe
- %WINDIR%\syswow64\del.bat
- %WINDIR%\syswow64\sup.exe
- %WINDIR%\syswow64\f.exe
- %WINDIR%\syswow64\redame.txt
- %WINDIR%\syswow64\hp120.exe
- %WINDIR%\syswow64\kp.exe
- %WINDIR%\syswow64\king.exe
- %WINDIR%\syswow64\internet explorer.url
- %WINDIR%\syswow64\hp.bat
- %WINDIR%\syswow64\internet explorer.lnk
- %WINDIR%\syswow64\hp.vbs
- %WINDIR%\syswow64\homep.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\5xif854a\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\dxy10gu6\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\552vtdm0\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\content.ie5\3wsv15m0\desktop.ini
- %TEMP%\nsua822.tmp\banner.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[1]
- '61.##4.62.83':1111
- http://61.###.62.83:1111/down.php?un################## via 61.##4.62.83
- DNS ASK le##tv.info
- DNS ASK d1.###xuntv.info
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%WINDIR%\syswow64\bbplay\bb.exe'
- '%WINDIR%\syswow64\f.exe'
- '%WINDIR%\syswow64\bbplayer.exe'
- '%WINDIR%\syswow64\hp120.exe'
- '%WINDIR%\syswow64\sup.exe'
- '%WINDIR%\syswow64\kp.exe'
- '%WINDIR%\syswow64\king.exe'
- '%WINDIR%\syswow64\homep.exe'
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\hp.vbs"
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\syswow64\WININET.dll",DispatchAPICall 1
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\hp.bat" "
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://61.##4.62.83:1111/down.php?union=yitian&agent=0' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\hp.bat" "' (with hidden window)