Technical Information
- <Current directory>\á÷ðçö®èð\<File name>.exe
- %HOMEPATH%\desktop\á÷ðçö®èð.lnk
- <Current directory>\á÷ðçö®èð\x_f_0.data
- <Current directory>\á÷ðçö®èð\data\bbzdywb.txt
- <Current directory>\á÷ðçö®èð\data\esp_ng.dat
- <Current directory>\á÷ðçö®èð\data\mapdesc1.dat
- <Current directory>\á÷ðçö®èð\data\mapdesc2.dat
- <Current directory>\á÷ðçö®èð\k018\data\52esp.pak
- <Current directory>\á÷ðçö®èð\k018\data\espcd.pak
- <Current directory>\á÷ðçö®èð\k018\data\espsc1.pak
- <Current directory>\á÷ðçö®èð\k018\data\esp_sdgh.pak
- <Current directory>\á÷ðçö®èð\k018\data\ui1.pak
- <Current directory>\á÷ðçö®èð\wav\sound.lst
- <Current directory>\á÷ðçö®èð\data\newopui.pak
- <Current directory>\á÷ðçö®èð\x_f_0.data
- 'lb##0.com':99
- 'ba##u.com':80
- http://www.lb###.com:99/BBCS.txt via lb##0.com
- http://www.ba##u.com/link.htm
- DNS ASK lb##0.com
- DNS ASK ba##u.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<Current directory>\á÷ðçö®èð\<File name>.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del /q <Full path to file>' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /q <Full path to file>