Technical Information
- %TEMP%\<File name>.exepack.tmp
- %TEMP%\a62926a96d5749730fbe8b0a56e9e5f3a.ini
- %TEMP%\a62926a96d5749730fbe8b0a56e9e5f3.ini
- %TEMP%\1a82ac.txt
- %TEMP%\²¹¶¡.zip
- <Current directory>\data\1108bcodedata.zip
- <Current directory>\data\jzlocab2.puk
- <Current directory>\data\md5.txt
- <Current directory>\gk\guhand.puk
- <Current directory>\gk\jzlocab2.puk
- <Current directory>\gk\logindll.puk
- <Current directory>\gk\В¦s+В¦md5.txt
- <Current directory>\ltcq2022\data\magicon.pak
- <Current directory>\wav\sound.lst
- <Current directory>\data\newopui.pak
- %TEMP%\a62926a96d5749730fbe8b0a56e9e5f3.ini
- %TEMP%\²¹¶¡.zip
- 'ht##q.com':80
- 'a.##sf.com':7000
- '12#.#29.217.215':57685
- http://www.ht##q.com/bmd.txt
- DNS ASK ht##q.com
- DNS ASK a.##sf.com
- '%WINDIR%\syswow64\cmd.exe' /c del "<Current directory>\*oclt.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "<Current directory>\*.dll"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "<Current directory>\*oclt.exe"
- '%WINDIR%\syswow64\cmd.exe' /c del "<Current directory>\*.dll"