Technical Information
- %PROGRAM_FILES%\soft050903\wl06079.exe
- %PROGRAM_FILES%\kws\Cookies.exe
- %PROGRAM_FILES%\soft050903\wl06079.exe (downloaded from the Internet)
- <SYSTEM32>\reg.exe add "HKCU\Software\VB and VBA Program Settings\baifen" /v "" /d "http://www.q7##7.com/" /f
- <SYSTEM32>\taskkill.exe /f /im explorer.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://ta##rl.com/4iklm
- <SYSTEM32>\ntvdm.exe -f -i1
- %WINDIR%\explorer.exe
- <SYSTEM32>\ntvdm.exe -f
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\soft050903\300.bat" "
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\soft050903\b_0503.vbe"
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.17##g.com/lianjie/10608.htm
- <SYSTEM32>\attrib.exe +s +h "<Drive name for removable media>:\Mozilla"
- %WINDIR%\regedit.exe /s 300.reg
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\soft050903\encrypt.bat" "
- %WINDIR%\Explorer.EXE
- C:\60.DLL
- %WINDIR%\Temp\scs57.tmp
- C:\61.DLL
- %WINDIR%\Temp\scs55.tmp
- C:\59.DLL
- %WINDIR%\Temp\scs56.tmp
- %WINDIR%\Temp\scs58.tmp
- %WINDIR%\Temp\scs5A.tmp
- C:\64.DLL
- %WINDIR%\Temp\scs5B.tmp
- C:\62.DLL
- %WINDIR%\Temp\scs59.tmp
- C:\63.DLL
- C:\58.DLL
- C:\53.DLL
- %WINDIR%\Temp\scs50.tmp
- C:\54.DLL
- %WINDIR%\Temp\scs4E.tmp
- C:\52.DLL
- %WINDIR%\Temp\scs4F.tmp
- %WINDIR%\Temp\scs51.tmp
- %WINDIR%\Temp\scs53.tmp
- C:\57.DLL
- %WINDIR%\Temp\scs54.tmp
- C:\55.DLL
- %WINDIR%\Temp\scs52.tmp
- C:\56.DLL
- %WINDIR%\Temp\scs64.tmp
- C:\74.DLL
- %WINDIR%\Temp\scs65.tmp
- C:\72.DLL
- %WINDIR%\Temp\scs63.tmp
- C:\73.DLL
- C:\75.DLL
- C:\77.DLL
- %WINDIR%\Temp\scs68.tmp
- C:\78.DLL
- %WINDIR%\Temp\scs66.tmp
- C:\76.DLL
- %WINDIR%\Temp\scs67.tmp
- %WINDIR%\Temp\scs62.tmp
- %WINDIR%\Temp\scs5D.tmp
- C:\67.DLL
- %WINDIR%\Temp\scs5E.tmp
- C:\65.DLL
- %WINDIR%\Temp\scs5C.tmp
- C:\66.DLL
- C:\68.DLL
- C:\70.DLL
- %WINDIR%\Temp\scs61.tmp
- C:\71.DLL
- %WINDIR%\Temp\scs5F.tmp
- C:\69.DLL
- %WINDIR%\Temp\scs60.tmp
- C:\33.DLL
- %WINDIR%\Temp\scs3C.tmp
- C:\34.DLL
- %WINDIR%\Temp\scs3A.tmp
- C:\32.DLL
- %WINDIR%\Temp\scs3B.tmp
- %WINDIR%\Temp\scs3D.tmp
- %WINDIR%\Temp\scs3F.tmp
- C:\37.DLL
- %WINDIR%\Temp\scs40.tmp
- C:\35.DLL
- %WINDIR%\Temp\scs3E.tmp
- C:\36.DLL
- C:\31.DLL
- C:\26.DLL
- %WINDIR%\Temp\scs35.tmp
- C:\27.DLL
- %WINDIR%\Temp\scs33.tmp
- C:\25.DLL
- %WINDIR%\Temp\scs34.tmp
- %WINDIR%\Temp\scs36.tmp
- %WINDIR%\Temp\scs38.tmp
- C:\30.DLL
- %WINDIR%\Temp\scs39.tmp
- C:\28.DLL
- %WINDIR%\Temp\scs37.tmp
- C:\29.DLL
- %WINDIR%\Temp\scs49.tmp
- C:\47.DLL
- %WINDIR%\Temp\scs4A.tmp
- C:\45.DLL
- %WINDIR%\Temp\scs48.tmp
- C:\46.DLL
- C:\48.DLL
- C:\50.DLL
- %WINDIR%\Temp\scs4D.tmp
- C:\51.DLL
- %WINDIR%\Temp\scs4B.tmp
- C:\49.DLL
- %WINDIR%\Temp\scs4C.tmp
- %WINDIR%\Temp\scs47.tmp
- %WINDIR%\Temp\scs42.tmp
- C:\40.DLL
- %WINDIR%\Temp\scs43.tmp
- C:\38.DLL
- %WINDIR%\Temp\scs41.tmp
- C:\39.DLL
- C:\41.DLL
- C:\43.DLL
- %WINDIR%\Temp\scs46.tmp
- C:\44.DLL
- %WINDIR%\Temp\scs44.tmp
- C:\42.DLL
- %WINDIR%\Temp\scs45.tmp
- C:\114.DLL
- %WINDIR%\Temp\scs8D.tmp
- C:\115.DLL
- %WINDIR%\Temp\scs8B.tmp
- C:\113.DLL
- %WINDIR%\Temp\scs8C.tmp
- %WINDIR%\Temp\scs8E.tmp
- %WINDIR%\Temp\scs90.tmp
- C:\118.DLL
- %WINDIR%\Temp\scs91.tmp
- C:\116.DLL
- %WINDIR%\Temp\scs8F.tmp
- C:\117.DLL
- C:\112.DLL
- C:\107.DLL
- %WINDIR%\Temp\scs86.tmp
- C:\108.DLL
- %WINDIR%\Temp\scs84.tmp
- C:\106.DLL
- %WINDIR%\Temp\scs85.tmp
- %WINDIR%\Temp\scs87.tmp
- %WINDIR%\Temp\scs89.tmp
- C:\111.DLL
- %WINDIR%\Temp\scs8A.tmp
- C:\109.DLL
- %WINDIR%\Temp\scs88.tmp
- C:\110.DLL
- %WINDIR%\Temp\scs9A.tmp
- C:\128.DLL
- %WINDIR%\Temp\scs9B.tmp
- C:\126.DLL
- %WINDIR%\Temp\scs99.tmp
- C:\127.DLL
- C:\129.DLL
- C:\131.DLL
- %WINDIR%\Temp\scs9E.tmp
- C:\132.DLL
- %WINDIR%\Temp\scs9C.tmp
- C:\130.DLL
- %WINDIR%\Temp\scs9D.tmp
- %WINDIR%\Temp\scs98.tmp
- %WINDIR%\Temp\scs93.tmp
- C:\121.DLL
- %WINDIR%\Temp\scs94.tmp
- C:\119.DLL
- %WINDIR%\Temp\scs92.tmp
- C:\120.DLL
- C:\122.DLL
- C:\124.DLL
- %WINDIR%\Temp\scs97.tmp
- C:\125.DLL
- %WINDIR%\Temp\scs95.tmp
- C:\123.DLL
- %WINDIR%\Temp\scs96.tmp
- C:\87.DLL
- %WINDIR%\Temp\scs72.tmp
- C:\88.DLL
- %WINDIR%\Temp\scs70.tmp
- C:\86.DLL
- %WINDIR%\Temp\scs71.tmp
- %WINDIR%\Temp\scs73.tmp
- %WINDIR%\Temp\scs75.tmp
- C:\91.DLL
- %WINDIR%\Temp\scs76.tmp
- C:\89.DLL
- %WINDIR%\Temp\scs74.tmp
- C:\90.DLL
- C:\85.DLL
- C:\80.DLL
- %WINDIR%\Temp\scs6B.tmp
- C:\81.DLL
- %WINDIR%\Temp\scs69.tmp
- C:\79.DLL
- %WINDIR%\Temp\scs6A.tmp
- %WINDIR%\Temp\scs6C.tmp
- %WINDIR%\Temp\scs6E.tmp
- C:\84.DLL
- %WINDIR%\Temp\scs6F.tmp
- C:\82.DLL
- %WINDIR%\Temp\scs6D.tmp
- C:\83.DLL
- %WINDIR%\Temp\scs7F.tmp
- C:\101.DLL
- %WINDIR%\Temp\scs80.tmp
- C:\99.DLL
- %WINDIR%\Temp\scs7E.tmp
- C:\100.DLL
- C:\102.DLL
- C:\104.DLL
- %WINDIR%\Temp\scs83.tmp
- C:\105.DLL
- %WINDIR%\Temp\scs81.tmp
- C:\103.DLL
- %WINDIR%\Temp\scs82.tmp
- %WINDIR%\Temp\scs7D.tmp
- %WINDIR%\Temp\scs78.tmp
- C:\94.DLL
- %WINDIR%\Temp\scs79.tmp
- C:\92.DLL
- %WINDIR%\Temp\scs77.tmp
- C:\93.DLL
- C:\95.DLL
- C:\97.DLL
- %WINDIR%\Temp\scs7C.tmp
- C:\98.DLL
- %WINDIR%\Temp\scs7A.tmp
- C:\96.DLL
- %WINDIR%\Temp\scs7B.tmp
- C:\24.DLL
- %PROGRAM_FILES%\chaoji_050903\Upgrade.ini
- %PROGRAM_FILES%\chaoji_050903\ico.ico
- %PROGRAM_FILES%\chaoji_050903\module.log
- %PROGRAM_FILES%\chaoji_050903\360SEUP.dll
- %PROGRAM_FILES%\chaoji_050903\ChaoJi.exe
- %PROGRAM_FILES%\chaoji_050903\ChaoJi.ini
- %PROGRAM_FILES%\chaoji_050903\passlist.dat
- %PROGRAM_FILES%\chaoji_050903\360\searchcore\SearchCfg.dat
- %PROGRAM_FILES%\chaoji_050903\360\searchcore\plugin.ini
- %PROGRAM_FILES%\chaoji_050903\360\searchcore\searchcore.dll
- %PROGRAM_FILES%\chaoji_050903\seext.dll
- %PROGRAM_FILES%\chaoji_050903\360\360core\360core.dll
- %PROGRAM_FILES%\chaoji_050903\360\360core\plugin.ini
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ Intarnot Explarer .lnk
- %PROGRAM_FILES%\Flush\plugin\360snap\screener.exe
- %PROGRAM_FILES%\Flush\plugin\360snap\snap.ico
- %PROGRAM_FILES%\Flush\plugin\koudai\add.htm
- %PROGRAM_FILES%\Flush\plugin\360Skinhelper\skinhelper.ico
- %PROGRAM_FILES%\Flush\plugin\360snap\360snap.dll
- %PROGRAM_FILES%\Flush\plugin\360snap\plugin.ini
- %PROGRAM_FILES%\Flush\plugin\koudai\add.ico
- %PROGRAM_FILES%\Flush\plugin\zconf\plugin.ini
- %PROGRAM_FILES%\Flush\plugin\zconf\quickconf.dll
- %ALLUSERSPROFILE%\Desktop\ Intarnot Explarer .lnk
- %PROGRAM_FILES%\Flush\plugin\koudai\plugin.ini
- %PROGRAM_FILES%\Flush\plugin\koudai\readme.txt
- %PROGRAM_FILES%\Flush\plugin\zconf\conf.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_7.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_8.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_9.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_4.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_5.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_6.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\Thumbs.db
- %PROGRAM_FILES%\chaoji_050903\ImgCache\jc.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\poker.wan.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\se.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\avc.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\down.chinaz.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\hao.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_3.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_11.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_12.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_13.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_0.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_1.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_10.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_14.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_18.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_19.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_2.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_15.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_16.bmp
- %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_17.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_11.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_12.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_13.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_0.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_1.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_10.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_14.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_18.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_19.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_2.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_15.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_16.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_17.bmp
- %PROGRAM_FILES%\Flush\360\searchcore\searchcore.dll
- %PROGRAM_FILES%\kws\AutoHotKeykws.ini
- %PROGRAM_FILES%\kws\Cookieskws.exe
- %PROGRAM_FILES%\Flush\Flush.exe
- %TEMP%\nse2.tmp\System.dll
- %PROGRAM_FILES%\kws\2kws.db
- %PROGRAM_FILES%\kws\3kws.db
- %PROGRAM_FILES%\Flush\Flush.ini
- %PROGRAM_FILES%\Flush\360\360core\plugin.ini
- %PROGRAM_FILES%\Flush\360\searchcore\SearchCfg.dat
- %PROGRAM_FILES%\Flush\360\searchcore\plugin.ini
- %PROGRAM_FILES%\Flush\module.log
- %PROGRAM_FILES%\Flush\passlist.dat
- %PROGRAM_FILES%\Flush\360\360core\360core.dll
- %PROGRAM_FILES%\Flush\ImgCache\www.46.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.58.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.886.la_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.3234.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.360.cn_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.360buy.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.baidu.com_favicon.ico
- %PROGRAM_FILES%\Flush\Shield\Sandboxie.ini
- %PROGRAM_FILES%\Flush\plugin\360Skinhelper\Skinhelper.dll
- %PROGRAM_FILES%\Flush\plugin\360Skinhelper\plugin.ini
- %PROGRAM_FILES%\Flush\ImgCache\www.ename.cn_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.google.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.qihoo.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.2345a.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_6.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_7.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_8.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_3.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_4.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_5.bmp
- %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_9.bmp
- %PROGRAM_FILES%\Flush\ImgCache\se.360.cn_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\wan.360.cn_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\www.2345.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\hao.360.cn_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\new.cnzz.com_favicon.ico
- %PROGRAM_FILES%\Flush\ImgCache\poker.wan.360.cn_favicon.ico
- %WINDIR%\Temp\scs15.tmp
- C:\17.DLL
- %WINDIR%\Temp\scs16.tmp
- C:\15.DLL
- %WINDIR%\Temp\scs14.tmp
- C:\16.DLL
- C:\18.DLL
- C:\19.DLL
- %WINDIR%\Temp\scs1A.tmp
- C:\20.DLL
- %WINDIR%\Temp\scs17.tmp
- %WINDIR%\Temp\scs18.tmp
- %WINDIR%\Temp\scs19.tmp
- %WINDIR%\Temp\scs13.tmp
- %WINDIR%\Temp\scsE.tmp
- C:\10.DLL
- %WINDIR%\Temp\scsF.tmp
- C:\8.DLL
- %WINDIR%\Temp\scsD.tmp
- C:\9.DLL
- C:\11.DLL
- C:\13.DLL
- %WINDIR%\Temp\scs12.tmp
- C:\14.DLL
- %WINDIR%\Temp\scs10.tmp
- C:\12.DLL
- %WINDIR%\Temp\scs11.tmp
- %WINDIR%\Temp\scs2C.tmp
- %WINDIR%\Temp\scs2D.tmp
- %WINDIR%\Temp\scs2E.tmp
- %WINDIR%\Temp\scs29.tmp
- %WINDIR%\Temp\scs2A.tmp
- %WINDIR%\Temp\scs2B.tmp
- %WINDIR%\Temp\scs2F.tmp
- %WINDIR%\Temp\scs31.tmp
- C:\23.DLL
- %WINDIR%\Temp\scs32.tmp
- C:\21.DLL
- %WINDIR%\Temp\scs30.tmp
- C:\22.DLL
- %WINDIR%\Temp\scs28.tmp
- %WINDIR%\Temp\scs1E.tmp
- %WINDIR%\Temp\scs1F.tmp
- %WINDIR%\Temp\scs20.tmp
- %WINDIR%\Temp\scs1B.tmp
- %WINDIR%\Temp\scs1C.tmp
- %WINDIR%\Temp\scs1D.tmp
- %WINDIR%\Temp\scs21.tmp
- %WINDIR%\Temp\scs25.tmp
- %WINDIR%\Temp\scs26.tmp
- %WINDIR%\Temp\scs27.tmp
- %WINDIR%\Temp\scs22.tmp
- %WINDIR%\Temp\scs23.tmp
- %WINDIR%\Temp\scs24.tmp
- %PROGRAM_FILES%\chaoji_050903\plugin\360snap\snap.ico
- %PROGRAM_FILES%\chaoji_050903\plugin\koudai\add.htm
- %PROGRAM_FILES%\chaoji_050903\plugin\koudai\add.ico
- %PROGRAM_FILES%\chaoji_050903\plugin\360snap\360snap.dll
- %PROGRAM_FILES%\chaoji_050903\plugin\360snap\plugin.ini
- %PROGRAM_FILES%\chaoji_050903\plugin\360snap\screener.exe
- %PROGRAM_FILES%\chaoji_050903\plugin\koudai\plugin.ini
- %ALLUSERSPROFILE%\Desktop\ МФ±¦-МШВф.lnk
- %PROGRAM_FILES%\soft050903\a
- %PROGRAM_FILES%\soft050903\encrypt.bat
- %PROGRAM_FILES%\chaoji_050903\plugin\zconf\conf.ico
- %PROGRAM_FILES%\chaoji_050903\plugin\zconf\plugin.ini
- %PROGRAM_FILES%\chaoji_050903\plugin\zconf\quickconf.dll
- %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\skinhelper.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.cnzz.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.google.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.qihoo.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\wan.360.cn_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.baidu.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.baidu123.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.taoku.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\360se_head.bmp
- %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\Skinhelper.dll
- %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\plugin.ini
- %PROGRAM_FILES%\chaoji_050903\ImgCache\www.yijia.com_favicon.ico
- %PROGRAM_FILES%\chaoji_050903\Shield\Sandboxie.ini
- %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\360se_default.gif
- C:\3.DLL
- %WINDIR%\Temp\scs8.tmp
- C:\4.DLL
- C:\2.DLL
- %WINDIR%\Temp\scs7.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\4iklm[1]
- %WINDIR%\Temp\scs9.tmp
- %WINDIR%\Temp\scsB.tmp
- C:\7.DLL
- %WINDIR%\Temp\scsC.tmp
- C:\5.DLL
- %WINDIR%\Temp\scsA.tmp
- C:\6.DLL
- %WINDIR%\Temp\scs6.tmp
- %PROGRAM_FILES%\soft050903\0320110305030320090305030303.txt
- %TEMP%\nse2.tmp\Math.dll
- %TEMP%\nse2.tmp\FindProcDLL.dll
- %PROGRAM_FILES%\soft050903\w_0503.exe
- %PROGRAM_FILES%\soft050903\B_0320110305030320090305030303.txt
- %PROGRAM_FILES%\soft050903\C_0320110305030320090305030303.txt
- %TEMP%\nse2.tmp\NSISdl.dll
- %WINDIR%\Temp\scs5.tmp
- C:\1.DLL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\10608[1].htm
- %WINDIR%\Temp\scs3.tmp
- %PROGRAM_FILES%\soft050903\wl06079.exe
- %WINDIR%\Temp\scs4.tmp
- %PROGRAM_FILES%\chaoji_050903\chaoji_050903.ini
- %PROGRAM_FILES%\Flush\Flush_050903.ini
- %WINDIR%\Temp\scs63.tmp
- %WINDIR%\Temp\scs62.tmp
- %WINDIR%\Temp\scs64.tmp
- %WINDIR%\Temp\scs66.tmp
- %WINDIR%\Temp\scs65.tmp
- %WINDIR%\Temp\scs61.tmp
- %WINDIR%\Temp\scs5D.tmp
- %WINDIR%\Temp\scs5C.tmp
- %WINDIR%\Temp\scs5E.tmp
- %WINDIR%\Temp\scs60.tmp
- %WINDIR%\Temp\scs5F.tmp
- %WINDIR%\Temp\scs6E.tmp
- %WINDIR%\Temp\scs6D.tmp
- %WINDIR%\Temp\scs6F.tmp
- %WINDIR%\Temp\scs71.tmp
- %WINDIR%\Temp\scs70.tmp
- %WINDIR%\Temp\scs6C.tmp
- %WINDIR%\Temp\scs68.tmp
- %WINDIR%\Temp\scs67.tmp
- %WINDIR%\Temp\scs69.tmp
- %WINDIR%\Temp\scs6B.tmp
- %WINDIR%\Temp\scs6A.tmp
- %WINDIR%\Temp\scs5B.tmp
- %WINDIR%\Temp\scs4C.tmp
- %WINDIR%\Temp\scs4B.tmp
- %WINDIR%\Temp\scs4D.tmp
- %WINDIR%\Temp\scs4F.tmp
- %WINDIR%\Temp\scs4E.tmp
- %WINDIR%\Temp\scs4A.tmp
- %WINDIR%\Temp\scs46.tmp
- %WINDIR%\Temp\scs45.tmp
- %WINDIR%\Temp\scs47.tmp
- %WINDIR%\Temp\scs49.tmp
- %WINDIR%\Temp\scs48.tmp
- %WINDIR%\Temp\scs57.tmp
- %WINDIR%\Temp\scs56.tmp
- %WINDIR%\Temp\scs58.tmp
- %WINDIR%\Temp\scs5A.tmp
- %WINDIR%\Temp\scs59.tmp
- %WINDIR%\Temp\scs55.tmp
- %WINDIR%\Temp\scs51.tmp
- %WINDIR%\Temp\scs50.tmp
- %WINDIR%\Temp\scs52.tmp
- %WINDIR%\Temp\scs54.tmp
- %WINDIR%\Temp\scs53.tmp
- %WINDIR%\Temp\scs90.tmp
- %WINDIR%\Temp\scs8F.tmp
- %WINDIR%\Temp\scs91.tmp
- %WINDIR%\Temp\scs93.tmp
- %WINDIR%\Temp\scs92.tmp
- %WINDIR%\Temp\scs8E.tmp
- %WINDIR%\Temp\scs8A.tmp
- %WINDIR%\Temp\scs89.tmp
- %WINDIR%\Temp\scs8B.tmp
- %WINDIR%\Temp\scs8D.tmp
- %WINDIR%\Temp\scs8C.tmp
- %WINDIR%\Temp\scs9B.tmp
- %WINDIR%\Temp\scs9A.tmp
- %WINDIR%\Temp\scs9C.tmp
- %WINDIR%\Temp\scs9E.tmp
- %WINDIR%\Temp\scs9D.tmp
- %WINDIR%\Temp\scs99.tmp
- %WINDIR%\Temp\scs95.tmp
- %WINDIR%\Temp\scs94.tmp
- %WINDIR%\Temp\scs96.tmp
- %WINDIR%\Temp\scs98.tmp
- %WINDIR%\Temp\scs97.tmp
- %WINDIR%\Temp\scs88.tmp
- %WINDIR%\Temp\scs79.tmp
- %WINDIR%\Temp\scs78.tmp
- %WINDIR%\Temp\scs7A.tmp
- %WINDIR%\Temp\scs7C.tmp
- %WINDIR%\Temp\scs7B.tmp
- %WINDIR%\Temp\scs77.tmp
- %WINDIR%\Temp\scs73.tmp
- %WINDIR%\Temp\scs72.tmp
- %WINDIR%\Temp\scs74.tmp
- %WINDIR%\Temp\scs76.tmp
- %WINDIR%\Temp\scs75.tmp
- %WINDIR%\Temp\scs84.tmp
- %WINDIR%\Temp\scs83.tmp
- %WINDIR%\Temp\scs85.tmp
- %WINDIR%\Temp\scs87.tmp
- %WINDIR%\Temp\scs86.tmp
- %WINDIR%\Temp\scs82.tmp
- %WINDIR%\Temp\scs7E.tmp
- %WINDIR%\Temp\scs7D.tmp
- %WINDIR%\Temp\scs7F.tmp
- %WINDIR%\Temp\scs81.tmp
- %WINDIR%\Temp\scs80.tmp
- %WINDIR%\Temp\scs44.tmp
- C:\2.DLL
- C:\1.DLL
- C:\3.DLL
- C:\5.DLL
- C:\4.DLL
- %WINDIR%\Temp\scs1A.tmp
- %WINDIR%\Temp\scs16.tmp
- %WINDIR%\Temp\scs15.tmp
- %WINDIR%\Temp\scs17.tmp
- %WINDIR%\Temp\scs19.tmp
- %WINDIR%\Temp\scs18.tmp
- C:\13.DLL
- C:\12.DLL
- C:\14.DLL
- C:\16.DLL
- C:\15.DLL
- C:\11.DLL
- C:\7.DLL
- C:\6.DLL
- C:\8.DLL
- C:\10.DLL
- C:\9.DLL
- %WINDIR%\Temp\scs14.tmp
- %WINDIR%\Temp\scs6.tmp
- %WINDIR%\Temp\scs5.tmp
- %PROGRAM_FILES%\soft050903\300.reg
- %WINDIR%\Temp\scs8.tmp
- %WINDIR%\Temp\scs7.tmp
- %WINDIR%\Temp\scs4.tmp
- %PROGRAM_FILES%\kws\3.db
- %PROGRAM_FILES%\kws\2.db
- %PROGRAM_FILES%\kws\AutoHotKey.ini
- %WINDIR%\Temp\scs3.tmp
- %PROGRAM_FILES%\soft050903\b_0503.vbe
- %WINDIR%\Temp\scs10.tmp
- %WINDIR%\Temp\scsF.tmp
- %WINDIR%\Temp\scs11.tmp
- %WINDIR%\Temp\scs13.tmp
- %WINDIR%\Temp\scs12.tmp
- %WINDIR%\Temp\scsE.tmp
- %WINDIR%\Temp\scsA.tmp
- %WINDIR%\Temp\scs9.tmp
- %WINDIR%\Temp\scsB.tmp
- %WINDIR%\Temp\scsD.tmp
- %WINDIR%\Temp\scsC.tmp
- %WINDIR%\Temp\scs35.tmp
- %WINDIR%\Temp\scs34.tmp
- %WINDIR%\Temp\scs36.tmp
- %WINDIR%\Temp\scs38.tmp
- %WINDIR%\Temp\scs37.tmp
- %WINDIR%\Temp\scs33.tmp
- %WINDIR%\Temp\scs2F.tmp
- %WINDIR%\Temp\scs2E.tmp
- %WINDIR%\Temp\scs30.tmp
- %WINDIR%\Temp\scs32.tmp
- %WINDIR%\Temp\scs31.tmp
- %WINDIR%\Temp\scs40.tmp
- %WINDIR%\Temp\scs3F.tmp
- %WINDIR%\Temp\scs41.tmp
- %WINDIR%\Temp\scs43.tmp
- %WINDIR%\Temp\scs42.tmp
- %WINDIR%\Temp\scs3E.tmp
- %WINDIR%\Temp\scs3A.tmp
- %WINDIR%\Temp\scs39.tmp
- %WINDIR%\Temp\scs3B.tmp
- %WINDIR%\Temp\scs3D.tmp
- %WINDIR%\Temp\scs3C.tmp
- %WINDIR%\Temp\scs2D.tmp
- %WINDIR%\Temp\scs1E.tmp
- %WINDIR%\Temp\scs1D.tmp
- %WINDIR%\Temp\scs1F.tmp
- %WINDIR%\Temp\scs21.tmp
- %WINDIR%\Temp\scs20.tmp
- %WINDIR%\Temp\scs1C.tmp
- C:\18.DLL
- C:\17.DLL
- C:\19.DLL
- %WINDIR%\Temp\scs1B.tmp
- C:\20.DLL
- %WINDIR%\Temp\scs29.tmp
- %WINDIR%\Temp\scs28.tmp
- %WINDIR%\Temp\scs2A.tmp
- %WINDIR%\Temp\scs2C.tmp
- %WINDIR%\Temp\scs2B.tmp
- %WINDIR%\Temp\scs27.tmp
- %WINDIR%\Temp\scs23.tmp
- %WINDIR%\Temp\scs22.tmp
- %WINDIR%\Temp\scs24.tmp
- %WINDIR%\Temp\scs26.tmp
- %WINDIR%\Temp\scs25.tmp
- from %PROGRAM_FILES%\soft050903\a to %PROGRAM_FILES%\soft050903\050903.txt
- from %PROGRAM_FILES%\chaoji_050903\ChaoJi.ini to %PROGRAM_FILES%\chaoji_050903\chaoji_050903.ini
- from %PROGRAM_FILES%\chaoji_050903\ChaoJi.exe to %PROGRAM_FILES%\chaoji_050903\chaoji_050903.exe
- from %PROGRAM_FILES%\soft050903\0320110305030320090305030303.txt to %PROGRAM_FILES%\soft050903\b_0503.vbe
- from %PROGRAM_FILES%\soft050903\C_0320110305030320090305030303.txt to %PROGRAM_FILES%\soft050903\300.reg
- from %PROGRAM_FILES%\soft050903\B_0320110305030320090305030303.txt to %PROGRAM_FILES%\soft050903\300.bat
- from %PROGRAM_FILES%\kws\AutoHotKeykws.ini to %PROGRAM_FILES%\kws\AutoHotKey.ini
- from %PROGRAM_FILES%\kws\3kws.db to %PROGRAM_FILES%\kws\3.db
- from %PROGRAM_FILES%\kws\2kws.db to %PROGRAM_FILES%\kws\2.db
- from %PROGRAM_FILES%\Flush\Flush.ini to %PROGRAM_FILES%\Flush\Flush_050903.ini
- from %PROGRAM_FILES%\Flush\Flush.exe to %PROGRAM_FILES%\Flush\Flush_050903.exe
- from %PROGRAM_FILES%\kws\Cookieskws.exe to %PROGRAM_FILES%\kws\Cookies.exe
- 'localhost':1041
- 'ta##rl.com':80
- 'oo.##mtb.info':888
- 'localhost':1036
- 'do##.emoney.cn':80
- 'www.17##g.com':80
- ta##rl.com/4iklm
- www.17##g.com/lianjie/10608.htm
- do##.emoney.cn/wl06079.exe
- DNS ASK ta##rl.com
- DNS ASK oo.##mtb.info
- DNS ASK do##.emoney.cn
- DNS ASK www.17##g.com
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'BaseBar' WindowName: 'ChanApp'
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-d50.d54.3a0001'
- ClassName: 'CSCHiddenWindow' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-abc.ac0.390002'
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''