Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run] 'llajyn_df' = '%WINDIR%\system\lljyn090509.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Network' = '<SYSTEM32>\ime\network.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'InterMoni' = '%WINDIR%\intermoni\InMonitor.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logondll] 'DllName' = 'fly5557.dll'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logondll] 'Startup' = 'EventStartup'
- [<HKLM>\SYSTEM\ControlSet001\Services\winmgmtex] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\msiiqk] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\tepwkpzz] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\kqvrmpgt] 'Start' = '00000000'
- <SYSTEM32>\dllcache\ipfltdrv.sys with <SYSTEM32>\dllcache\ipfltdrv.sys.new
- <DRIVERS>\ipfltdrv.sys with <DRIVERS>\ipfltdrv.sys.txt
- %WINDIR%\kqvrmpgt.exe
- %TEMP%\InternetMonitor3002.exe
- %TEMP%\spools.exe
- %TEMP%\Messenger\setup.exe llly
- <SYSTEM32>\aehko.exe
- %TEMP%\lnvsvc32.exe
- <SYSTEM32>\aehko.exe /service
- %TEMP%\svchosts.exe
- %TEMP%\kzd2009.exe
- %TEMP%\small66.exe
- %TEMP%\lqbz82.exe
- %TEMP%\selvice.exe
- %TEMP%\llly66.exe
- %WINDIR%\tepwkpzz.exe
- <SYSTEM32>\cmd.exe /c %TEMP%\tmp.bat
- <SYSTEM32>\ping.exe 127.0.0.1
- <SYSTEM32>\net1.exe start winmgmtex
- <SYSTEM32>\rundll32.exe "<SYSTEM32>\zvspl.dll",DllCanUnloadNow
- <SYSTEM32>\cmd.exe /c ""c:\dfDelmlljy.bat" "
- <SYSTEM32>\regsvr32.exe /s /u %WINDIR%\FlashAssistant.dll
- <SYSTEM32>\sc.exe create msiiqk type= kernel start= auto binpath= <DRIVERS>\msiiqk.sys
- <SYSTEM32>\regsvr32.exe /s <SYSTEM32>\IEMaster.dll
- <SYSTEM32>\sc.exe stop ipfilterdriver
- <SYSTEM32>\regsvr32.exe /s <SYSTEM32>\flyplug.dll
- <SYSTEM32>\ntsd.exe -c q -p 1576
- <SYSTEM32>\sc.exe start ipfilterdriver
- <SYSTEM32>\cmd.exe /c %TEMP%\dsetup.bat
- %WINDIR%\Explorer.EXE
- 360tray.exe
- NtQueryDirectoryFile, handler: nmrychob.sys
- NtQuerySystemInformation, handler: nmrychob.sys
- NtEnumerateKey, handler: nmrychob.sys
- NtEnumerateValueKey, handler: nmrychob.sys
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
- %WINDIR%\tepwkpzz.exe
- %WINDIR%\kqvrmpgt.exe
- %TEMP%\lnvsvc32.exe
- %TEMP%\tmp.tmp
- %WINDIR%\intermoni\InMonitor.exe
- C:\dfDelmlljy.bat
- %WINDIR%\system\llbjyn32bb.dll
- %TEMP%\tmp.bat
- <SYSTEM32>\mssrcid.ini
- %WINDIR%\kqvrmpgt.exe
- <DRIVERS>\nmrychob.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\downloader_4005[1].gif
- %ALLUSERSPROFILE%\lljyndf16.ini
- %WINDIR%\system\lljyn090509.exe
- <SYSTEM32>\Web.ini
- <SYSTEM32>\adorder.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\gt[1].asp
- %WINDIR%\repair\er8049
- %WINDIR%\Temp\Messenger\kbietmp2.ini
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\index[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\lin[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\131[1]
- %WINDIR%\Temp\Messenger\zdgjn.ini
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\update[1].htm
- %WINDIR%\repair\js1838
- %WINDIR%\inf\gjf3520
- %WINDIR%\msagent\bc6133.tlb
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Explorer дЇААЖч.lnk
- %TEMP%\InternetMonitor3002.exe
- %TEMP%\spools.exe
- %TEMP%\selvice.exe
- <SYSTEM32>\flyplug.dll
- <DRIVERS>\aeyvwesk.sys
- <SYSTEM32>\flymain.dll
- %TEMP%\kzd2009.exe
- %TEMP%\small66.exe
- %TEMP%\nsw2.tmp
- %TEMP%\llly66.exe
- %TEMP%\lqbz82.exe
- %TEMP%\svchosts.exe
- %WINDIR%\tepwkpzz.exe
- <SYSTEM32>\fly5557.dll
- %TEMP%\Messenger\twain_32.dll
- %TEMP%\Messenger\sysvc.dat
- <DRIVERS>\msiiqk.log
- %TEMP%\dsetup.bat
- <SYSTEM32>\dllcache\fly5557.dll
- <SYSTEM32>\IEMaster.dll
- %TEMP%\3.tmp
- %WINDIR%\inf\qbv6122.PNF
- %TEMP%\Messenger\sysmain.dat
- %TEMP%\Messenger\setup.exe
- %TEMP%\Messenger\nvsys.ini
- %TEMP%\svchosts.exe
- %TEMP%\tmp.tmp
- %TEMP%\spools.exe
- %TEMP%\lqbz82.exe
- %TEMP%\kzd2009.exe
- <DRIVERS>\ipfltdrv.sys
- %TEMP%\3.tmp
- %TEMP%\selvice.exe
- from %TEMP%\Messenger\sysmain.dat to <SYSTEM32>\zvspl.dll
- from <DRIVERS>\ipfltdrv.sys.new to <DRIVERS>\ipfltdrv.sys
- from %TEMP%\Messenger\nvsys.ini to <SYSTEM32>\awtqm.ini
- from <DRIVERS>\msiiqk.log to <DRIVERS>\msiiqk.sys
- from %TEMP%\Messenger\sysvc.dat to <SYSTEM32>\aehko.exe
- 'xa####.11ave.net':80
- 'www.k-#c.cn':80
- 'xy#.###2009new1.com.cn':80
- 'xa##.11ave.net':80
- 'pt#.otrd.cn':80
- 'xa###.11ave.net':80
- 'www.66##.8800.org':80
- 'ms#.#912345.com':80
- 'localhost':1036
- 'www.13#.cc':80
- 'm1.##battery.cn':80
- 'localhost':1045
- xa###.11ave.net/cike.php?fi#################################################
- xa####.11ave.net/cike.php?fi#################################################
- pt#.otrd.cn/cike.php?fi#################################################
- m1.##battery.cn/myconfig/index.htm
- xa##.11ave.net/cike.php?fi#################################################
- xy#.###2009new1.com.cn/count.php?fi#################################################
- www.66##.8800.orghttp://www.6666.8800.org/Start.htm?Ar#####################################################################################################
- ms#.#912345.com/html/downloader_4005.gif
- m1.##battery.cn/up/update.htm
- m1.##battery.cn/page/gt.asp?ve#############################################################################################
- www.13#.cc/
- www.k-#c.cn//lin//lin.asp
- DNS ASK www.13#.cc
- DNS ASK m1.##battery.cn
- DNS ASK xa##.11ave.net
- DNS ASK www.ba##u.com
- DNS ASK www.k-#c.cn
- DNS ASK id#.#kaka.com
- DNS ASK xy#.###2009new1.com.cn
- DNS ASK www.66##.8800.org
- DNS ASK ms#.#912345.com
- DNS ASK xa####.11ave.net
- DNS ASK pt#.otrd.cn
- DNS ASK xa###.11ave.net
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'AUTOLIVE_CLASS_C7DC1F21-713F-4585-913D-C253689E97A5' WindowName: 'AUTOLIVE_WND_C7DC1F21-713F-4585-913D-C253689E97A5'
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'CabinetWClass' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Indicator' WindowName: ''