Technical Information
- '%PROGRAM_FILES%\duoduo\migu.exe'
- '%PROGRAM_FILES%\duoduo\df.exe'
- '%PROGRAM_FILES%\YoudaoDict_zhusha_heima_0112.exe' /S
- '%PROGRAM_FILES%\duoduo\DDVInstall.exe'
- '%PROGRAM_FILES%\yiqmon2868.exe'
- '%PROGRAM_FILES%\duoduo\box.exe'
- '%PROGRAM_FILES%\duoduo\ckj.exe'
- '%PROGRAM_FILES%\duoduo\hao.exe'
- '%PROGRAM_FILES%\duoduo\yd.exe'
- '%PROGRAM_FILES%\YoudaoDict_zhusha_heima_0112.exe' (downloaded from the Internet)
- '%PROGRAM_FILES%\yiqmon2868.exe' (downloaded from the Internet)
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://60##6.net/tj2.php?g=###############
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.mo###sbaidu.cn/
- %HOMEPATH%\Start Menu\360°ІИ«дЇААЖч.lnk
- %HOMEPATH%\Start Menu\Internet Explorer.lnk
- %HOMEPATH%\Favorites\ґуµЁИЛМеТХКх.lnk
- %HOMEPATH%\Favorites\№ИёидЇААЖч.lnk
- %HOMEPATH%\Start Menu\Гв·СФЪПЯµзУ°.lnk
- %HOMEPATH%\Start Menu\ОТµД°Щ±¦Пд.lnk
- %HOMEPATH%\Start Menu\ґуµЁИЛМеТХКх.lnk
- %HOMEPATH%\Start Menu\ЙПНшµјєЅ.lnk
- %HOMEPATH%\Start Menu\МФ±¦ЙМіЗ.lnk
- %HOMEPATH%\Favorites\ОТµД°Щ±¦Пд.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ґуµЁИЛМеТХКх.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\№ИёидЇААЖч.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МФ±¦ЙМіЗ.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ОТµД°Щ±¦Пд.lnk
- %HOMEPATH%\Favorites\360°ІИ«дЇААЖч.lnk
- %HOMEPATH%\Favorites\ЙПНшµјєЅ.lnk
- %HOMEPATH%\Favorites\МФ±¦ЙМіЗ.lnk
- %HOMEPATH%\Favorites\Internet Explorer.lnk
- %HOMEPATH%\Favorites\Гв·СФЪПЯµзУ°.lnk
- %HOMEPATH%\Start Menu\№ИёидЇААЖч.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\yiqmon2868[1].exe
- %PROGRAM_FILES%\yiqmon2868.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mm[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a[1].htm
- %TEMP%\nsa8.tmp\inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\YoudaoDict_zhusha_heima_0112[1].exe
- %PROGRAM_FILES%\YoudaoDict_zhusha_heima_0112.exe
- %TEMP%\nsyA.tmp\inetc.dll
- %TEMP%\nsj6.tmp\inetc.dll
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %HOMEPATH%\Desktop\Гв·СФЪПЯµзУ°.lnk
- %TEMP%\nsa4.tmp\inetc.dll
- %HOMEPATH%\Desktop\360°ІИ«дЇААЖч.lnk
- %HOMEPATH%\Desktop\ЙПНшµјєЅ.lnk
- %HOMEPATH%\Desktop\ґуµЁИЛМеТХКх.lnk
- %HOMEPATH%\Desktop\№ИёидЇААЖч.lnk
- %HOMEPATH%\Desktop\МФ±¦ЙМіЗ.lnk
- %HOMEPATH%\Desktop\ОТµД°Щ±¦Пд.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ЙПНшµјєЅ.lnk
- %PROGRAM_FILES%\duoduo\res\b_logo_1.bmp
- %PROGRAM_FILES%\duoduo\res\logo_1.bmp
- %PROGRAM_FILES%\duoduo\res\91555game.ico
- %PROGRAM_FILES%\duoduo\res\Thumbs.db
- %PROGRAM_FILES%\rar\36.ico
- %PROGRAM_FILES%\rar\chrome.ico
- %PROGRAM_FILES%\rar\daohang.ico
- %PROGRAM_FILES%\rar\360°ІИ«дЇААЖч.lnk
- %PROGRAM_FILES%\rar\Internet Explorer.lnk
- %PROGRAM_FILES%\duoduo\yd.exe
- %PROGRAM_FILES%\duoduo\DDVInstall.exe
- %PROGRAM_FILES%\duoduo\box.exe
- %PROGRAM_FILES%\duoduo\53l4Vf5vM6g==.txt
- %PROGRAM_FILES%\duoduo\Client.ini
- %PROGRAM_FILES%\duoduo\ckj.exe
- %PROGRAM_FILES%\duoduo\migu.exe
- %PROGRAM_FILES%\duoduo\wp.exe
- %PROGRAM_FILES%\duoduo\df.exe
- %PROGRAM_FILES%\duoduo\hao.exe
- %PROGRAM_FILES%\rar\i.ico
- %HOMEPATH%\Start Menu\Programs\МФ±¦ЙМіЗ.lnk
- %HOMEPATH%\Start Menu\Programs\ОТµД°Щ±¦Пд.lnk
- %HOMEPATH%\Start Menu\Programs\Гв·СФЪПЯµзУ°.lnk
- %HOMEPATH%\Start Menu\Programs\ЙПНшµјєЅ.lnk
- %HOMEPATH%\Start Menu\Programs\ґуµЁИЛМеТХКх.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Гв·СФЪПЯµзУ°.lnk
- %HOMEPATH%\Start Menu\Programs\№ИёидЇААЖч.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\360°ІИ«дЇААЖч.lnk
- %HOMEPATH%\Start Menu\Programs\360°ІИ«дЇААЖч.lnk
- %PROGRAM_FILES%\rar\taobao.ico
- %PROGRAM_FILES%\rar\ґуµЁИЛМеТХКх.lnk
- %PROGRAM_FILES%\rar\mm.ico
- %PROGRAM_FILES%\rar\movie.ico
- %PROGRAM_FILES%\rar\№ИёидЇААЖч.lnk
- %PROGRAM_FILES%\rar\МФ±¦ЙМіЗ.lnk
- %PROGRAM_FILES%\rar\ОТµД°Щ±¦Пд.lnk
- %PROGRAM_FILES%\rar\Гв·СФЪПЯµзУ°.lnk
- %PROGRAM_FILES%\rar\ЙПНшµјєЅ.lnk
- %TEMP%\nsj6.tmp\inetc.dll
- %TEMP%\nsa4.tmp\inetc.dll
- 'localhost':1112
- '58.##8.199.187':28080
- 'dl.##ima8.com':80
- '60.##1.222.214':6066
- 'do##.49558.cn':80
- 'www.le##tv.info':80
- 'localhost':1036
- 'localhost':1041
- 'localhost':1040
- do##.49558.cn/soft/yiqmon2868.exe
- dl.##ima8.com/uncode/104157791/dl/YoudaoDict_zhusha_heima/.exe/YoudaoDict_zhusha_heima_0112.exe
- www.le##tv.info/box/mm.htm
- www.le##tv.info/box/a.htm
- DNS ASK 60##6.net
- DNS ASK dl.##ima8.com
- DNS ASK www.91##5.com
- DNS ASK www.le##tv.info
- DNS ASK do##.49558.cn
- DNS ASK www.mo###sbaidu.cn
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'