Technical Information
- '%ProgramFiles%\internet explorer\iexplore.exe' http://bbs.llv8.com
- '%ProgramFiles%\internet explorer\iexplore.exe' http://www.llv8.com
- '%ProgramFiles%\internet explorer\iexplore.exe' http://56blog.net
- <Current directory>\skinh_el.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\dnserrordiagoff[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\dnserrordiagoff[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\newerrorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\history\desktop.ini
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-696f2d19-d60.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-696f2d19-448.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-696f2d1e-c48.pma
- <Current directory>\skinh_el.dll
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\dnserrordiagoff[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\dnserrordiagoff[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\newerrorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\newerrorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\httperrorpagesscripts[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\newerrorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\newerrorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\httperrorpagesscripts[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\hd-header-logo-v3[1].svg
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\phone-icon-white[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\search-icon-white[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\phone-icon[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\favorite-header[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\cart[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\30daysmallico[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\roket-side-ico[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\safesmallico[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\zero-side-ico[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\sucses-item-4[1].jpg
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\mail-icon[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\h0tpijss\sucses-item-arrow[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\footer-logo-1[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\footer-logo-2[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\6po53e98\footer-logo-3[1].png
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\7702vlxi\jquery.fancybox.min[1].css
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\bullet[2]
- %LOCALAPPDATA%\microsoft\edge\user data\last version
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\site characteristics database\log
- %LOCALAPPDATA%\microsoft\tokenbroker\cache\9cd93bc6dcf544bae69531052e64647ec02f2bb4.tbres
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t3zgcaj5\dnserrordiagoff[1]
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Platform Notifications\LOG
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG
- 'sh###iandao.cn':80
- 'bb#.#lv8.com':80
- 'st####.hugedomains.com':443
- '19#.#32.210.172':80
- '23.##0.163.238':80
- 'cd####okieyes.com':443
- 'cd#.##delivr.net':443
- 'fo###.#oogleapis.com':443
- 'us#.#ypekit.net':443
- 'go#####agmanager.com':443
- 'google.com':443
- 'p.###ekit.net':443
- 'fo###.gstatic.com':443
- 'yo##ube.com':443
- 'gs##tic.com':443
- 'co####.edge.skype.com':443
- 'go######s.g.doubleclick.net':443
- 'st####.doubleclick.net':443
- 'i.##img.com':443
- 'yt#.#gpht.com':443
- 'sh###iandao.cn':443
- 'jn####.googleapis.com':443
- http://www.ll##.com/
- http://bb#.#lv8.com/
- http://www.sh###iandao.cn/ceshi/xinsui.html
- 'st####.hugedomains.com':443
- '15#.#01.193.91':443
- 'cd####okieyes.com':443
- 'cd#.##delivr.net':443
- 'fo###.#oogleapis.com':443
- 'us#.#ypekit.net':443
- 'go#####agmanager.com':443
- 'google.com':443
- 'p.###ekit.net':443
- 'yo##ube.com':443
- 'gs##tic.com':443
- 'co####.edge.skype.com':443
- 'go######s.g.doubleclick.net':443
- 'st####.doubleclick.net':443
- 'i.##img.com':443
- 'yt#.#gpht.com':443
- 'sh###iandao.cn':443
- 'jn####.googleapis.com':443
- DNS ASK dn##lsh.com
- DNS ASK sh###iandao.cn
- DNS ASK wx##h.com
- DNS ASK sf.#214.cn
- DNS ASK bb#.#lv8.com
- DNS ASK ll##.com
- DNS ASK hu###omains.com
- DNS ASK cd####okieyes.com
- DNS ASK cd#.##delivr.net
- DNS ASK st####.hugedomains.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK us#.#ypekit.net
- DNS ASK go#####agmanager.com
- DNS ASK google.com
- DNS ASK p.###ekit.net
- DNS ASK fo###.gstatic.com
- DNS ASK yo##ube.com
- DNS ASK gs##tic.com
- DNS ASK co####.edge.skype.com
- DNS ASK go######s.g.doubleclick.net
- DNS ASK st####.doubleclick.net
- DNS ASK i.##img.com
- DNS ASK yt#.#gpht.com
- DNS ASK jn####.googleapis.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Microsoft\Edge\User Data'
- '%ProgramFiles(x86)%\microsoft\edge\application\89.0.774.68\bho\ie_to_edge_stub.exe' --from-ie-to-edge=3 --ie-frame-hwnd=7002e
- '%ProgramFiles(x86)%\microsoft\edge\application\89.0.774.68\bho\ie_to_edge_stub.exe' --from-ie-to-edge=3 --ie-frame-hwnd=d0288
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --from-ie-to-edge=3 --ie-frame-hwnd=7002e
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --from-ie-to-edge=3 --ie-frame-hwnd=d0288
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --from-ie-to-edge=3 --ie-frame-hwnd=7002e --flag-switches-begin --flag-switches-end --do-not-de-elevate
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --from-ie-to-edge=3 --ie-frame-hwnd=7002e --flag-switches-begin --flag-switches-end --do-not-de-elevate' (with hidden window)