Technical Information
- %WINDIR%\system.ini
- <Current directory>\config_l.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\zmuktniv\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\ea09503g\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\zmuktniv\bullet[1]
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %WINDIR%\ff.e
- 'tu##u.com':80
- 'tu##u.com':443
- 'yo##u.com':80
- 'yo##u.com':443
- 'g.###cdn.com':443
- http://www.tu##u.com/cate/?tp########################################
- http://www.yo##u.com/?de#################
- 'tu##u.com':443
- 'yo##u.com':443
- 'g.###cdn.com':443
- DNS ASK i.###nsp.com
- DNS ASK u.###nsp.com
- DNS ASK tu##u.com
- DNS ASK yo##u.com
- DNS ASK g.###cdn.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Shell Embedding' WindowName: ''
- ClassName: 'Shell DocObject View' WindowName: ''
- ClassName: 'internet explorer_server' WindowName: ''