Техническая информация
- %WINDIR%\Help\yuyanzhe.dat
- %APPDATA%\YueG.dll
- <SYSTEM32>\SkinH_EL.dll
- <SYSTEM32>\imedllhost08.ime
- <SYSTEM32>\Hook.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kuk5[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\51cfwg[1]
- %WINDIR%\Help\yuyanzhe.dat
- %TEMP%\51cfwg\downlib.fne
- %TEMP%\51cfwg\HtmlView.fne
- %TEMP%\51cfwg\dp1.fne
- %TEMP%\51cfwg\krnln.fnr
- %TEMP%\51cfwg\shell.fne
- %TEMP%\51cfwg\eAPI.fne
- %TEMP%\51cfwg\internet.fne
- %TEMP%\51cfwg\PBShell.fne
- 'www.ku##.com':80
- 'www.97##f.com':80
- 'localhost':1036
- 'www.51##wg.com':80
- www.97##f.com/1.txt
- www.ku##.com/
- www.51##wg.com/
- DNS ASK www.97##f.com
- DNS ASK www.ku##.com
- DNS ASK www.51##wg.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''