Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinQvod] 'Start' = '00000002'
- '%TEMP%\App.exe'
- '%CommonProgramFiles%\Microsoft Shared\MSInfo\exploer.exe'
- '%PROGRAM_FILES%\iphone3_kzt\Run.exe'
- '%PROGRAM_FILES%\iphone3_kzt\safe_lotto.exe'
- '%PROGRAM_FILES%\iphone3_kzt\lotto.exe'
- %PROGRAM_FILES%\iphone3_kzt\Run.exe
- %HOMEPATH%\Desktop\iphone3_控制台.lnk
- %CommonProgramFiles%\Microsoft Shared\MSInfo\exploer.exe
- %TEMP%\App.exe
- %PROGRAM_FILES%\iphone3_kzt\update\type.wav
- %PROGRAM_FILES%\iphone3_kzt\safe_lotto.exe
- %PROGRAM_FILES%\iphone3_kzt\lotto.exe
- %PROGRAM_FILES%\iphone3_kzt\update\set.ini
- %PROGRAM_FILES%\iphone3_kzt\update\beep1.wav
- %CommonProgramFiles%\Microsoft Shared\MSInfo\exploer.exe
- 'sh####ing.1qdan.com':8010
- '12#.#25.114.144':80
- 12#.#25.114.144/wengjinfei/item/e2fde421c17debd10f37f9c0
- DNS ASK sh####ing.1qdan.com
- DNS ASK .#.
- DNS ASK hi.##idu.com
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'