Technical Information
- %TEMP%\vcredist_x86.exe /Q
- %PROGRAM_FILES%\Baidu\AddressBar\ASBarBroker.exe -RegServer
- %TEMP%\BaiduGameLobby.exe
- %TEMP%\setup_133daohang2.exe /S
- %TEMP%\aoyou.exe
- %TEMP%\setup_000024.exe
- %TEMP%\hahayx1.exe
- %TEMP%\Setupnn.exe
- %TEMP%\BaiduGameLobby.exe (downloaded from the Internet)
- %TEMP%\vcredist_x86.exe (downloaded from the Internet)
- %TEMP%\setup_133daohang2.exe (downloaded from the Internet)
- <SYSTEM32>\cmd.exe /c %TEMP%\$$30689.bat
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\Baidu\BaiduGame\install.vbs"
- %TEMP%\vcredist_x86.exe.dt!
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\setup_133daohang2[1].exe
- %TEMP%\setup_133daohang2.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\百度地址栏\卸载百度地址栏.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\data[1].ini
- %TEMP%\data.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\lcun709[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\lcun709[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lcun709[1].txt
- %TEMP%\$$30689.bat
- %TEMP%\XVHMZYHZPNP.zbc
- %TEMP%\BaiduGameLobby.exe.dt!
- %PROGRAM_FILES%\Baidu\BaiduGame\lobbyconfig.xml
- %TEMP%\Setupnn.exe
- %TEMP%\hahayx1.exe
- %HOMEPATH%\Favorites\====133НшЦ·Ц®јТ====.URL
- %TEMP%\nsl2.tmp\System.dll
- %TEMP%\setup_000024.exe
- %TEMP%\aoyou.exe
- %TEMP%\nsl2.tmp\ShellLink.dll
- %PROGRAM_FILES%\Baidu\AddressBar\AddressBar.dll
- %PROGRAM_FILES%\Baidu\AddressBar\ASBarBroker.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\百度地址栏\百度地址栏官网.url
- %TEMP%\nsi4.tmp
- %TEMP%\nst5.tmp\InetLoad2.dll
- %PROGRAM_FILES%\Baidu\AddressBar\AddressBar_Tmp\AddressBar.dll
- %TEMP%\XVHMZYHZPNP.zbc
- %TEMP%\Setupnn.exe
- %TEMP%\data.ini
- %TEMP%\nsl2.tmp\ShellLink.dll
- %TEMP%\nsl2.tmp\System.dll
- 'hi##.qqjes.com':80
- 'www.ga###baidu.com':80
- 'do##.#amesbaidu.com':80
- 'localhost':1038
- 'mk.##xthon.cn':80
- hi##.qqjes.com/pages/lcun709.txt
- www.ga###baidu.com/down.asp?id##############
- mk.##xthon.cn/133daohang2/setup_133daohang2.exe
- mk.##xthon.cn/online_inst/data.ini
- do##.#amesbaidu.com/vcredist_x86.exe
- DNS ASK do##.#amesbaidu.com
- DNS ASK hi##.qqjes.com
- DNS ASK www.ga###baidu.com
- DNS ASK ud#.#job123.com
- DNS ASK mk.##xthon.cn
- 'ud#.#job123.com':31803
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''