Technical Information
- Handler for all processes: <Current directory>\cfgdll.dll
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\mac62f6.tmp
- C:\´óììê¹\Г§В°Гù¼óµã2.bmp
- C:\´óììê¹\×£¸£ê¯.bmp
- C:\´óììê¹\âêñå.bmp
- C:\´óììê¹\êà ½çµøГВј1.bmp
- C:\´óììê¹\ëø¶¨.bmp
- C:\´óììê¹\½»ò׳鹦.bmp
- C:\´óììê¹\×£¸£ê¯1.bmp
- C:\´óììê¹\×£¸£ê¯2.bmp
- C:\´óììê¹\âêñå1.bmp
- C:\´óììê¹\¿ªê¼1.bmp
- C:\´óììê¹\âêñå2.bmp
- C:\´óììê¹\âêñå3.bmp
- C:\´óììê¹\½»ò×±êö¾1.bmp
- C:\´óììê¹\ëæéГéìµê1.bmp
- C:\´óììê¹\ç¿öæ¹ø±õ.bmp
- C:\´óììê¹\1ïß2.bmp
- C:\´óììê¹\½»ò×±êö¾2.bmp
- C:\´óììê¹\½»ò׳鹦1.bmp
- C:\´óììê¹\×¢ïú.bmp
- C:\´óììê¹\×£¸£ê¯3.bmp
- C:\´óììê¹\ВґГîó.bmp
- C:\´óììê¹\ð¡ºì.bmp
- C:\´óììê¹\êà ½çµøГВј.bmp
- C:\´óììê¹\ëµã÷.bmp
- C:\´óììê¹\ëæéГéìµê.bmp
- C:\´óììê¹\ìáê¾.bmp
- C:\´óììê¹\ìáê¾1.bmp
- C:\´óììê¹\Гæ¼ö¼óµã.bmp
- C:\´óììê¹\ïòóò¹ø.bmp
- C:\´óììê¹\ïò×ó¿ª.bmp
- C:\´óììê¹\ð¡à ¶.bmp
- C:\´óììê¹\×ô¶¯ìôõ½¸±±¾.bmp
- C:\´óììê¹\ð⹦äü.bmp
- C:\´óììê¹\ðå¼þ.bmp
- C:\´óììê¹\ðå¼þ1.bmp
- C:\´óììê¹\ðå¼þ2.bmp
- C:\´óììê¹\óâõß´óâ½.bmp
- C:\´óììê¹\ôú¹ò»ú.bmp
- C:\´óììê¹\öðºì.bmp
- C:\´óììê¹\öðà ¶.bmp
- C:\´óììê¹\æá±î1.bmp
- C:\´óììê¹\áé»ê±¦ê¯1.bmp
- C:\´óììê¹\dm.dll
- C:\´óììê¹\´óììê¹1.txt
- C:\´óììê¹\ВѕВ.bmp
- C:\´óììê¹\äê.bmp
- C:\´óììê¹\ê®.bmp
- C:\´óììê¹\³öêû6.bmp
- C:\´óììê¹\³öêû5.bmp
- C:\´óììê¹\³öêû4.bmp
- C:\´óììê¹\³öêû3.bmp
- C:\´óììê¹\³öêû2.bmp
- C:\´óììê¹\³öêû1.bmp
- C:\´óììê¹\ëø¶¨1.bmp
- C:\´óììê¹\ВµГ.bmp
- C:\´óììê¹\ВґГîó3.bmp
- C:\´óììê¹\½ðש.bmp
- C:\´óììê¹\à 뿪¸±±¾.bmp
- C:\´óììê¹\à 뿪¸±±¾2.bmp
- C:\´óììê¹\ВґГîóµä.bmp
- C:\´óììê¹\´óììê¹×¨óã.dll
- C:\´óììê¹\õëºå.txt
- C:\´óììê¹\µä.bmp
- C:\´óììê¹\ê¹óã.bmp
- C:\´óììê¹\mu.bmp
- C:\´óììê¹\áé»ê±¦ê¯.bmp
- C:\´óììê¹\ñûçë.bmp
- C:\´óììê¹\¹ø±õñûçë.bmp
- C:\´óììê¹\¹ø±õ4.bmp
- C:\´óììê¹\½øèëóîï·.bmp
- C:\´óììê¹\×¢ïú1.bmp
- C:\´óììê¹\áì衽±à ø1.bmp
- C:\´óììê¹\ВґГîó1.bmp
- C:\´óììê¹\óâõß´óâ½1.bmp
- C:\´óììê¹\êà ½çµøГВј2.bmp
- C:\´óììê¹\configuration.ini
- C:\´óììê¹\éúãü±¦ê¯.bmp
- C:\´óììê¹\óðã«.bmp
- C:\´óììê¹\óðã«1.bmp
- C:\´óììê¹\ВґГîó2.bmp
- C:\´óììê¹\×¢ïú2.bmp
- C:\´óììê¹\×¢ïú3.bmp
- C:\´óììê¹\½øèëóîï·1.bmp
- C:\´óììê¹\ГўГéïµçâ½.bmp
- C:\´óììê¹\êç.bmp
- C:\´óììê¹\âô.bmp
- C:\´óììê¹\èõ³£.bmp
- C:\´óììê¹\áì衽±à ø.bmp
- C:\´óììê¹\Г¦ГГґВё1.bmp
- C:\´óììê¹\穵½2.bmp
- C:\´óììê¹\Г§В°Гùèîîñ1.bmp
- C:\´óììê¹\è·¶¨1.bmp
- C:\´óììê¹\ê¹óã1.bmp
- C:\´óììê¹\Гæ¼ö¼óµã1.bmp
- C:\´óììê¹\ð⹦äü1.bmp
- C:\´óììê¹\×ô¶¯ìôõ½¸±±¾1.bmp
- C:\´óììê¹\npc.bmp
- C:\´óììê¹\¶à öø¼ý.bmp
- C:\´óììê¹\´´½¨½çé«.bmp
- C:\´óììê¹\´óºì.bmp
- C:\´óììê¹\´óà ¶.bmp
- C:\´óììê¹\´óììê¹.txt
- C:\´óììê¹\´óììê¹2.txt
- C:\´óììê¹\µçâ½.bmp
- C:\´óììê¹\µè¼¶.bmp
- C:\´óììê¹\µø.bmp
- C:\´óììê¹\áì衽±à ø5.bmp
- C:\´óììê¹\1ïß.bmp
- C:\´óììê¹\áì衽±à ø4.bmp
- %APPDATA%\qmacro\shield\sd002.dat
- %TEMP%\mac6307.tmp
- %TEMP%\plugin.zip
- <Current directory>\cfgdll.dll
- <Current directory>\shieldmodule.dat
- %APPDATA%\mymacro\qdisp.dll
- %TEMP%\2dce2c2.tmp
- %APPDATA%\qmacro\shield\sd000.dat
- %APPDATA%\qmacro\shield\sd001.dat
- %APPDATA%\qmacro\shield\sd003.dat
- C:\´óììê¹\ᢼ´×°±¸1.bmp
- %APPDATA%\qmacro\shield\sd004.dat
- %APPDATA%\qmacro\shield\shield.ini
- C:\´óììê¹\¹ò1.bmp
- C:\´óììê¹\¹ø±õ6.bmp
- C:\´óììê¹\¹ø±õ7.bmp
- C:\´óììê¹\¼ìðøèîîñ1.bmp
- C:\´óììê¹\à 뿪¸±±¾1.bmp
- C:\´óììê¹\ᢼ´²é¿´1.bmp
- C:\´óììê¹\áì衽±à ø3.bmp
- C:\´óììê¹\»ö¸´.bmp
- C:\´óììê¹\Г§В°Гùèîîñ.bmp
- C:\´óììê¹\¹³×ó.bmp
- C:\´óììê¹\à ¶.bmp
- C:\´óììê¹\ᢼ´²é¿´.bmp
- C:\´óììê¹\ᢼ´²é¿´2.bmp
- C:\´óììê¹\ᢼ´ìåñé.bmp
- C:\´óììê¹\ᢼ´×°±¸.bmp
- C:\´óììê¹\áäìì.bmp
- C:\´óììê¹\áìè¡.bmp
- C:\´óììê¹\áìè¡1.bmp
- C:\´óììê¹\áì衽±à ø2.bmp
- C:\´óììê¹\¹´ñ¡.bmp
- C:\´óììê¹\ä§.bmp
- C:\´óììê¹\æá±î.bmp
- C:\´óììê¹\Г¦ГГґВё.bmp
- C:\´óììê¹\ç©.bmp
- C:\´óììê¹\穵½.bmp
- C:\´óììê¹\穵½1.bmp
- C:\´óììê¹\Г§В°Гù¼óµã.bmp
- C:\´óììê¹\Г§В°Гù¼óµã1.bmp
- C:\´óììê¹\à ®°è.bmp
- C:\´óììê¹\è·¶¨.bmp
- C:\´óììê¹\¿ìëù½øèë.bmp
- C:\´óììê¹\ºì.bmp
- C:\´óììê¹\¹ò.bmp
- C:\´óììê¹\¹ò»ú.bmp
- C:\´óììê¹\¹ø±õ.bmp
- C:\´óììê¹\¹ø±õ1.bmp
- C:\´óììê¹\¹ø±õ2.bmp
- C:\´óììê¹\¹ø±õ3.bmp
- C:\´óììê¹\¹ø±õ5.bmp
- C:\´óììê¹\¹ø±õóîï·.bmp
- C:\´óììê¹\¸ü¶à .bmp
- C:\´óììê¹\¿ªæôæГГґВё.bmp
- C:\´óììê¹\¼ìðøèîîñ.bmp
- C:\´óììê¹\½»ò×.bmp
- C:\´óììê¹\½»ò×1.bmp
- C:\´óììê¹\½»ò×2.bmp
- C:\´óììê¹\½»ò×3.bmp
- C:\´óììê¹\½»ò×±êö¾.bmp
- C:\´óììê¹\½ð±ò.bmp
- C:\´óììê¹\¿ª·þ.bmp
- C:\´óììê¹\¿ªê¼.bmp
- C:\´óììê¹\regdll.dll
- %TEMP%\plugin.zip
- <Current directory>\shieldmodule.dat
- 'c.###huoa.com':80
- http://c.###huoa.com/c2/MymacroidSalesUrl.aspx?my#######################
- DNS ASK c.###huoa.com
- ClassName: '18467-41' WindowName: ''