Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'QQ¶Ь' = '%PROGRAM_FILES%\NetMeeting\v32\TXOCInstallUserConfigOE.exe -s'
- file extensions
- C:\qqskill.exe
- %PROGRAM_FILES%\NetMeeting\v32\TXOCInstallUserConfigOE.exe
- <SYSTEM32>\wscript.exe c:\t163.js
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\navihistory.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\menuicon.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\preview.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\new.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\img_progress.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\img_lock.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\mask.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\img_sideols.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\privacy.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\scrollbg.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\restore.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\search.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\scrollgauge.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\rebar_grip.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\rebar.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\refresh_combine.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\refresh.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\edit.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\dropdown.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_add.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\favorites.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\BTN_SIDEMASK.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\BTN_SIDECLOSE.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\chevron.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\BTN_SIDEMENU.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_directory.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\forward.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\findbaritem.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\home.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\go.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_net_nologin.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_net_login.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_url.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\fav_sidebar.ico
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\title_max2.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\title_max.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tool.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\title_min.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\titlebarmax.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\titlebar.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\title_cus.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\title_close.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\toolbar.png
- %PROGRAM_FILES%\TheWorld 3\КАЅзЦ®ґ°.url
- %PROGRAM_FILES%\TheWorld 3\TheWorld.ini
- %TEMP%\nsz10.tmp\AccessControl.dll
- %HOMEPATH%\Start Menu\Programs\КАЅзЦ®ґ°\Website.lnk
- %HOMEPATH%\Start Menu\Programs\КАЅзЦ®ґ°\КАЅзЦ®ґ°.lnk
- %PROGRAM_FILES%\TheWorld 3\TheWorld.exe
- %PROGRAM_FILES%\TheWorld 3\WebApp.exe
- %HOMEPATH%\Desktop\КАЅзЦ®ґ°.lnk
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\statusitem.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\skin.ini
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\stop_combine.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\stop.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\select.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\search.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\sizestatus.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\sep.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tabitem.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_new.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_drag.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\thumb.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_progress.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_button_close.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_button.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_color.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\tab_close.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\btn_sidebar_show.png
- %PROGRAM_FILES%\winrar\v32\shf.dat
- %TEMP%\nsr2.tmp\ns3.tmp
- %TEMP%\nsr2.tmp\ns5.tmp
- %TEMP%\nsr2.tmp\ns4.tmp
- %PROGRAM_FILES%\winrar\v32\360se.gif
- %PROGRAM_FILES%\winrar\v32\ff.gif
- %TEMP%\nsr2.tmp\nsExec.dll
- %PROGRAM_FILES%\winrar\v32\sg.gif
- %TEMP%\nsr2.tmp\ns6.tmp
- %PROGRAM_FILES%\NetMeeting\v32\Factory.dll
- %PROGRAM_FILES%\NetMeeting\v32\TXOCInstallUserConfigOE.exe
- %TEMP%\nsr2.tmp\nsB.tmp
- %TEMP%\nsr2.tmp\System.dll
- %TEMP%\nsr2.tmp\ns8.tmp
- %TEMP%\nsr2.tmp\ns7.tmp
- %TEMP%\nsr2.tmp\nsA.tmp
- %TEMP%\nsr2.tmp\ns9.tmp
- %PROGRAM_FILES%\winrar\v32\ФЪПЯСФЗйРЎЛµФД¶Б.url
- %PROGRAM_FILES%\winrar\v32\НЕ№є_ГлЙ±Нш.url
- %PROGRAM_FILES%\winrar\v32\xyx.pat
- %PROGRAM_FILES%\winrar\v32\tb.gif
- %PROGRAM_FILES%\winrar\v32\°¬µПЙо¶ИЛСЛч.url
- %PROGRAM_FILES%\winrar\v32\88yyФЪПЯРЎУОП·.url
- %PROGRAM_FILES%\winrar\v32\МФ±¦МШВф.url
- %PROGRAM_FILES%\winrar\v32\К®Т»ЅЦµҐ»ъУОП·.url
- %PROGRAM_FILES%\winrar\v32\ie.pat
- %PROGRAM_FILES%\winrar\v32\xyx.gif
- %TEMP%\nsr2.tmp\VPatch.dll
- %PROGRAM_FILES%\winrar\v32\tt.gif
- %PROGRAM_FILES%\winrar\v32\ie.gif
- %PROGRAM_FILES%\winrar\v32\ff.pat
- %PROGRAM_FILES%\winrar\v32\tt.pat
- %PROGRAM_FILES%\winrar\v32\sg.pat
- %PROGRAM_FILES%\winrar\v32\360se.pat
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_pagebar.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\backward.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_sidebar_tool.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_sidebar_mini.png
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtProxy\ExtProxy.dll
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtPages\ExtPages.dll
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\address.png
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtSuggest\ExtSuggest.dll
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_sidepanel.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\BTN_CLOSE.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\borderright.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\btn_sidebar_hide.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\BTN_LINE.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_toolbar.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\bg_sidetoolbar.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\borderleft.png
- %PROGRAM_FILES%\TheWorld 3\skin\Crystal_Chrome\borderbottom.png
- C:\TWSetup1.jpg
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Intrenet Exq1orer .exe
- %TEMP%\nsr2.tmp\nsC.tmp
- C:\TWSetup2.jpg
- %HOMEPATH%\Desktop\ОТµДРЎУОП·.exe
- C:\t163.js
- %HOMEPATH%\Desktop\Intrenet Exq1orer .exe
- %HOMEPATH%\Desktop\МФЦ®±¦.exe
- C:\shf.dat
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtAdfilter\ExtAdfilter.dll
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtAddons\ExtAddons.dll
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtMinibar\ExtMinibar.dll
- %PROGRAM_FILES%\TheWorld 3\Extensions\ExtDownload\ExtDownload.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\index400[1].htm
- %TEMP%\nsr2.tmp\nsD.tmp
- %TEMP%\nsr2.tmp\nsE.tmp
- C:\qqskill.exe
- C:\t163.js
- %TEMP%\nsr2.tmp\nsB.tmp
- %TEMP%\nsr2.tmp\nsA.tmp
- %TEMP%\nsr2.tmp\nsC.tmp
- C:\TWSetup2.jpg
- C:\TWSetup1.jpg
- %TEMP%\nsr2.tmp\nsD.tmp
- %TEMP%\nsr2.tmp\ns5.tmp
- %TEMP%\nsr2.tmp\ns4.tmp
- %TEMP%\nsr2.tmp\ns3.tmp
- %TEMP%\nsr2.tmp\ns6.tmp
- %TEMP%\nsr2.tmp\ns9.tmp
- %TEMP%\nsr2.tmp\ns8.tmp
- %TEMP%\nsr2.tmp\ns7.tmp
- 'ww#.cz3.net':80
- 'localhost':1037
- ww#.cz3.net/index400.htm
- DNS ASK ww#.cz3.net
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''