Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\ìúñ¶qq
- %TEMP%\is-6q177.tmp\<File name>.tmp
- %TEMP%\etilqs_u55ldiqgehwizeg
- %TEMP%\etilqs_qm2thxuzvx54swn
- %TEMP%\etilqs_5ivtxlrtgc26cig
- %TEMP%\etilqs_cqe55uigacgzunn
- %TEMP%\etilqs_ek5ddt9uhyjxpbt
- %TEMP%\etilqs_3erma2fljbh8wwl
- %TEMP%\etilqs_kjoxhwlmowfb4de
- C:\users\public\desktop\intentâìé«ä¯à à æ÷ 3
- C:\users\public\desktop\ìô±¦ГГё
- %ProgramFiles(x86)%\mmbrowser\êà ½çö®´°.ini
- %ProgramFiles(x86)%\mmbrowser\oem.ini
- %ProgramFiles(x86)%\mmbrowser\qq.txt
- %ProgramFiles(x86)%\mmbrowser\is-dka64.tmp
- %ProgramFiles(x86)%\mmbrowser\is-hfd54.tmp
- %ProgramFiles(x86)%\mmbrowser\is-qnscc.tmp
- %ProgramFiles(x86)%\mmbrowser\is-9rjum.tmp
- %ProgramFiles(x86)%\mmbrowser\is-t5ojq.tmp
- %ProgramFiles(x86)%\mmbrowser\is-9kuas.tmp
- %ProgramFiles(x86)%\mmbrowser\is-mdoe4.tmp
- %ProgramFiles(x86)%\mmbrowser\is-tqt6r.tmp
- %ProgramFiles(x86)%\mmbrowser\is-1doke.tmp
- %ProgramFiles(x86)%\mmbrowser\is-jo6u0.tmp
- %ProgramFiles(x86)%\mmbrowser\is-gs28v.tmp
- %ProgramFiles(x86)%\mmbrowser\is-pip40.tmp
- %TEMP%\is-e6u98.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-e6u98.tmp\_isetup\_setup64.tmp
- %TEMP%\is-e6u98.tmp\_isetup\_regdll.tmp
- %TEMP%\etilqs_qrdrq5qlxrttk55
- %TEMP%\etilqs_pewmrbunvpbm0qv
- %TEMP%\is-e6u98.tmp\_isetup\_regdll.tmp
- %TEMP%\is-e6u98.tmp\_isetup\_setup64.tmp
- %TEMP%\is-e6u98.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-6q177.tmp\<File name>.tmp
- from %ProgramFiles(x86)%\mmbrowser\is-pip40.tmp to %ProgramFiles(x86)%\mmbrowser\qq.ico
- from %ProgramFiles(x86)%\mmbrowser\qqico.ico to %APPDATA%\qqico.ico
- from C:\users\public\desktop\intentâìé«ä¯à à æ÷ 3 to C:\users\public\desktop\intentâìé«ä¯à à æ÷ 3.lnk
- from %ProgramFiles(x86)%\mmbrowser\ie.ico to %ProgramFiles%\internet explorer\ie.ico
- from C:\users\public\desktop\ìô±¦ГГё to C:\users\public\desktop\ìô±¦ГГё.lnk
- from %ProgramFiles(x86)%\mmbrowser\is-dka64.tmp to %ProgramFiles(x86)%\mmbrowser\êà ½çö®´°.exe
- from %ProgramFiles(x86)%\mmbrowser\is-hfd54.tmp to %ProgramFiles(x86)%\mmbrowser\oem.ini
- from %ProgramFiles(x86)%\mmbrowser\is-qnscc.tmp to %ProgramFiles(x86)%\mmbrowser\aa.ini
- from %ProgramFiles(x86)%\mmbrowser\is-9rjum.tmp to %ProgramFiles(x86)%\mmbrowser\ie.ico
- from %ProgramFiles(x86)%\mmbrowser\is-t5ojq.tmp to %ProgramFiles(x86)%\mmbrowser\shop.ico
- from %ProgramFiles(x86)%\mmbrowser\is-9kuas.tmp to %ProgramFiles(x86)%\mmbrowser\qq.txt
- from %ProgramFiles(x86)%\mmbrowser\is-mdoe4.tmp to %ProgramFiles(x86)%\mmbrowser\refreshdesktop.exe
- from %ProgramFiles(x86)%\mmbrowser\is-tqt6r.tmp to %ProgramFiles(x86)%\mmbrowser\mmnphpe.exe
- from %ProgramFiles(x86)%\mmbrowser\is-1doke.tmp to %ProgramFiles(x86)%\mmbrowser\uninstall.exe
- from %ProgramFiles(x86)%\mmbrowser\is-jo6u0.tmp to %ProgramFiles(x86)%\mmbrowser\voidfun.exe
- from %ProgramFiles(x86)%\mmbrowser\is-gs28v.tmp to %ProgramFiles(x86)%\mmbrowser\qqico.ico
- from %ProgramFiles(x86)%\mmbrowser\qq.txt to %APPDATA%\microsoft_qq
- from %ProgramFiles(x86)%\mmbrowser\refreshdesktop.exe to %WINDIR%\refreshdesktop.exe
- 'u.###123.net':80
- 'ok##d.com':80
- 'au######te.geo.opera.com':80
- 'au######te.geo.opera.com':443
- 'google.com':80
- 'se####.yahoo.com':80
- 'am##on.com':80
- 'du###uckgo.com':443
- 'bing.com':80
- 'en.###ipedia.org':80
- 'am##on.com':443
- 'se####.yahoo.com':443
- 'en.###ipedia.org':443
- 'si#####ck2.opera.com':80
- http://www.ok##d.com/Report_111518/ZJPlayerDown_8938/Player_Count_uuu_12.php?ty#########################################
- http://au######te.geo.opera.com/geolocation/
- http://www.google.com/favicon.ico
- http://www.am##on.com/favicon.ico
- http://se####.yahoo.com/favicon.ico
- http://www.bing.com/s/a/bing_p.ico
- http://en.###ipedia.org/favicon.ico
- http://si#####ck2.opera.com/?ho###################################################
- 'au######te.geo.opera.com':443
- 'du###uckgo.com':443
- 'am##on.com':443
- 'se####.yahoo.com':443
- 'en.###ipedia.org':443
- DNS ASK u.###123.net
- DNS ASK ok##d.com
- DNS ASK google.com
- DNS ASK au######te.geo.opera.com
- DNS ASK se####.yahoo.com
- DNS ASK am##on.com
- DNS ASK du###uckgo.com
- DNS ASK bing.com
- DNS ASK bi##.#ikimedia.org
- DNS ASK en.###ipedia.org
- DNS ASK si#####ck2.opera.com
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Opera Software\Opera Stable'
- '%TEMP%\is-6q177.tmp\<File name>.tmp' /SL5="$60240,695225,61440,<Full path to file>"
- '%ProgramFiles(x86)%\mmbrowser\voidfun.exe'
- '%ProgramFiles(x86)%\mmbrowser\mmnphpe.exe'
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "http://u.mok123.net/t1.htm"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.11.47161237\612441209" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.10.303461095\918175982" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.9.1742581636\528852823" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.8.1317800915\518398135" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.6.955133593\1206830411" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.7.448954253\568650300" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.5.1090678625\816945521" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' --type=utility --channel="1032.4.917635560\87822277" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001 /crash-reporter-parent-id=2068
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.4.917635560\87822277" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.12.1337253389\230599601" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --extension-process --enable-we...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="2884.0.1068843997\814342279" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="1032.0.1142483517\1843470107" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gp...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- http://u.mok123.net/t2.htm /crash-reporter-parent-id=2884
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- http://u.mok123.net/t1.htm /crash-reporter-parent-id=1032
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- http://u.mok123.net/t2.htm
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- http://u.mok123.net/t1.htm
- '%WINDIR%\syswow64\cmd.exe' /c del C:\PROGRA~2\MMBROW~1\voidfun.exe > nul
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "http://u.mok123.net/t2.htm"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --disable-client-side-phishing-...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1032.16.1002457802\1725705371" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%WINDIR%\syswow64\cmd.exe' /c del C:\PROGRA~2\MMBROW~1\voidfun.exe > nul' (with hidden window)