Technical Information
- Handler for all processes: <Current directory>\iskq.dll
- <Current directory>\plugin\Office.dll
- <Current directory>\plugin\Pic.dll
- <Current directory>\plugin\Sys.dll
- <Current directory>\plugin\Memory.dll
- <Current directory>\plugin\Msg.dll
- <Current directory>\plugin\Net.dll
- %TEMP%\2
- %TEMP%\4.tmp
- %TEMP%\їЄї5.tmp
- <Current directory>\plugin\Web.dll
- <Current directory>\plugin\Window.dll
- <Current directory>\iskq.dll
- <Current directory>\plugin\Media.dll
- <SYSTEM32>\qdisp.dll
- <Current directory>\temp02.dll
- <Current directory>\plugin\Bkgnd.dll
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %TEMP%\mymacro.zip
- <Current directory>\plugin\Encrypt.dll
- <Current directory>\plugin\File.dll
- <Current directory>\plugin\GetSysInfo.dll
- <Current directory>\plugin\BkgndColor.dll
- <Current directory>\plugin\Color.dll
- <Current directory>\plugin\Console.dll
- %TEMP%\2
- %TEMP%\4.tmp
- %TEMP%\mymacro.zip
- <Current directory>\temp02.dll
- 'c.##rj.cn':80
- http://c.##rj.cn/banner/Q01037.htm
- DNS ASK c.##rj.cn