Trojan.Win32.FlyStudio_9d47568b31
GenericEmailWorm.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 9d47568b311bab588769ba0807e9bfd2
SHA1: a18ae0de689207fdfeaa6cb76cc3804688a9858b
SHA256: e1c802419d8ddde3a881e4564e6118b05dc87259f54fdbb76f1f01f34b22e121
SSDeep: 196608:0pTYySW79JWxISFCdIac4njpZzN7E5Ih3fVc6mBMcKeDJb23MfBRrueCnz:0Snq9MdaIX4nh7E6h3tfcMcFDJb2wCzz
Size: 8428416 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2014-07-11 08:40:10
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
| Behaviour | Description |
|---|---|
| EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
%original file name%.exe:1044
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:1044 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TPHNX2CD\core[1].php (751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WH6BWP6F\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W1IFKDIZ\z_stat[1].php (1097 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5PN7CW2U\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W1IFKDIZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.°´ÃÂÂüƬ.tmp (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WH6BWP6F\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\9d47568b311bab588769ba0807e9bfd2.ini (381 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TPHNX2CD\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ø±Õ.µãȼüƬ.tmp (824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5PN7CW2U\jy.38kc[1].htm (359 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×îữ.Õý³£Ã¼Ƭ.tmp (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×îữ.µãȼüƬ.tmp (824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\µ×ü.tmp (189 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\DLQ.ini (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\pack.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ø±Õ.Õý³£Ã¼Ƭ.tmp (14 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\pack.tmp (0 bytes)
Registry activity
The process %original file name%.exe:1044 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CF 71 1B AF FF CC 36 F7 C8 A1 71 C0 DA 9E 20 FC"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| UPX0 | 4096 | 3235840 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| UPX1 | 3239936 | 5455872 | 5452288 | 5.39586 | 8588bb018963a8f9f6d9153d51ae9425 |
| .rsrc | 8695808 | 24576 | 21504 | 3.14518 | ff8b158e71331a921912a92a2e7dbd8d |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://jy.38kc.com/ | |
| hxxp://all.cnzz.com.danuoyi.tbcache.com/z_stat.php?id=1253004038 | |
| hxxp://z.gds.cnzz.com/stat.htm?id=1253004038&r=&lg=en-us&ntime=none&cnzz_eid=1959928650-1424968782-&showp=1276x846&t=&h=1&rnd=535817321 | |
| hxxp://all.cnzz.com.danuoyi.tbcache.com/core.php?web_id=1253004038&t=z | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1886823750 | |
| hxxp://s95.cnzz.com/z_stat.php?id=1253004038 | |
| hxxp://c.cnzz.com/core.php?web_id=1253004038&t=z | |
| hxxp://z4.cnzz.com/stat.htm?id=1253004038&r=&lg=en-us&ntime=none&cnzz_eid=1959928650-1424968782-&showp=1276x846&t=&h=1&rnd=535817321 | |
| pcookie.cnzz.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: jy.38kc.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Length: 359
Content-Type: text/html
Content-Location: hXXp://jy.38kc.com/index.htm
Last-Modified: Wed, 19 Nov 2014 15:31:33 GMT
Accept-Ranges: bytes
ETag: "f81f32e6d4d01:c00"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 26 Feb 2015 16:39:17 GMT<html>..<body>..<script type="text/javascript">var c
nzz_protocol = (("https:" == document.location.protocol) ? " hXXps://"
: " hXXp://");document.write(unescape(""
));</script>..<br>..</html>HTTP/1.1 200 OK..Content-
Length: 359..Content-Type: text/html..Content-Location: hXXp://jy.38kc
.com/index.htm..Last-Modified: Wed, 19 Nov 2014 15:31:33 GMT..Accept-R
anges: bytes..ETag: "f81f32e6d4d01:c00"..Server: Microsoft-IIS/6.0..X-
Powered-By: ASP.NET..Date: Thu, 26 Feb 2015 16:39:17 GMT..<html>
..<body>..<script type="text/javascript">var cnzz_protocol
= (("https:" == document.location.protocol) ? " hXXps://" : " hXXp://
");document.write(unescape("%
3C/span>"));</scri
pt>..<br>..</html>..
GET /9.gif?abc=1&rnd=1886823750 HTTP/1.1
Accept: */*
Referer: hXXp://jy.38kc.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 26 Feb 2015 16:39:44 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=UDp2DQ/YlxgCAcGK9Oe0QUOr; expires=Sun, 23-Feb-25 16:39:44 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=180594b3; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=e16a4df096434d94a808eb5a_1424968784; expires=Sun, 23-Feb-25 16:39:44 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=UDp2DQ/YlxgCAcGK9Oe0QUOr
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 26 Feb 2015 16:39:44 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=UDp2DQ/Ylx
gCAcGK9Oe0QUOr; expires=Sun, 23-Feb-25 16:39:44 GMT; path=/; domain=.m
mstat.com..Set-Cookie: sca=180594b3; path=/; domain=.cnzz.mmstat.com..
Set-Cookie: atpsida=e16a4df096434d94a808eb5a_1424968784; expires=Sun,
23-Feb-25 16:39:44 GMT; path=/; domain=.cnzz.mmsta..
GET /core.php?web_id=1253004038&t=z HTTP/1.1
Accept: */*
Referer: hXXp://jy.38kc.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/javascript
Content-Length: 751
Connection: keep-alive
Date: Thu, 26 Feb 2015 16:39:43 GMT
Last-Modified: Thu, 26 Feb 2015 16:39:43 GMT
Expires: Thu, 26 Feb 2015 16:54:43 GMT
Via: cache40.l2de1[310,200-0,M], cache64.l2de1[311,0], cache4.de1[311,200-0,M], cache1.de1[311,0]
X-Cache: MISS TCP_REFRESH_MISS dirn:-2:-2
X-Swift-SaveTime: Thu, 26 Feb 2015 16:39:44 GMT
X-Swift-CacheTime: 899!function(){var p,q,r,a=encodeURIComponent,b="1253004038",c="",d="",e=
"online_v3.php",f="z4.cnzz.com",g="1",h="text",i="z",j="站
1;统计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0
",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f
),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.c
allRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScr
iptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?web
_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.com/img
/" c ".gif",p="<a href='" q "' target=_blank title='" j "'><i
mg border=0 hspace=0 vspace=0 src='" r "'></a>"):p="<a hre
f='" q "' target=_blank title='" j "'>" j "</a>",k.createIcon
([p])))}();HTTP/1.1 200 OK..Server: Tengine..Content-Type: application
/javascript..Content-Length: 751..Connection: keep-alive..Date: Thu, 2
6 Feb 2015 16:39:43 GMT..Last-Modified: Thu, 26 Feb 2015 16:39:43 GMT.
.Expires: Thu, 26 Feb 2015 16:54:43 GMT..Via: cache40.l2de1[310,200-0,
M], cache64.l2de1[311,0], cache4.de1[311,200-0,M], cache1.de1[311,0]..
X-Cache: MISS TCP_REFRESH_MISS dirn:-2:-2..X-Swift-SaveTime: Thu, 26 F
eb 2015 16:39:44 GMT..X-Swift-CacheTime: 899..!function(){var p,q,r,a=
encodeURIComponent,b="1253004038",c="",d="",e="online_v3.php",f="z4.cn
zz.com",g="1",h="text",i="z",j="站长统计",k=wi
ndow["_CNZZDbridge_" b].bobject,l="http:",m="0",n=l "//online.cnzz.com
/online/" e,o=[];o.push("id=" b),o.push("h=" f),o.push("on=" a(d))<<< skipped >>>
GET /stat.htm?id=1253004038&r=&lg=en-us&ntime=none&cnzz_eid=1959928650-1424968782-&showp=1276x846&t=&h=1&rnd=535817321 HTTP/1.1
Accept: */*
Referer: hXXp://jy.38kc.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: z4.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 26 Feb 2015 16:39:43 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /z_stat.php?id=1253004038 HTTP/1.1
Accept: */*
Referer: hXXp://jy.38kc.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s95.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Date: Thu, 26 Feb 2015 16:39:42 GMT
Last-Modified: Thu, 26 Feb 2015 16:39:42 GMT
Cache-Control: max-age=5400,s-maxage=5400
Via: cache49.l2de1[1320,200-0,M], cache30.l2de1[1320,0], cache2.de1[1320,200-0,M], cache4.de1[1321,0]
X-Cache: MISS TCP_REFRESH_MISS dirn:-2:-2
X-Swift-SaveTime: Thu, 26 Feb 2015 16:39:42 GMT
X-Swift-CacheTime: 540029b..(function(){function k(){this.c="1253004038";this.R="z";this.N=""
;this.K="";this.M="";this.r="1424968782";this.P="z4.cnzz.com";this.L="
";this.u="CNZZDATA" this.c;this.t="_CNZZDbridge_" this.c;this.F="_cnzz
_CV" this.c;this.G="CZ_UUID" this.c;this.v="0";this.A={};this.a={};thi
s.la()}function g(a,b){try{var c=.[];c.push("siteid=1253004038");c.pus
h("name=" f(a.name));c.push("msg=" f(a.message));c.push("r=" f(h.refer
rer));c.push("page=" f(e.location.href));c.push("agent=" f(e.navigator
.userAgent));c.push("ex=" f(b));c.push("rnd=" Math.floor(2147483648*Ma
th.random()));(new Image).src="hXXp://jserr.cnzz.com/log.php?" c.join(
"&")}catch(d){}}var h=document,e=window,f=..24c0..encodeURIComponent,l
=decodeURIComponent,n=unescape,p=escape;k.prototype={la:function(){try
{this.U(),this.J(),this.ia(),this.H(),this.o(),.this.ga(),this.fa(),th
is.ja(),this.j(),this.ea(),this.ha(),this.ka(),this.ca(),this.aa(),thi
s.da(),this.qa(),e[this.t]=e[this.t]||{},this.ba("_cnzz_CV")}catch(a){
g(a,"i failed")}},oa:function(){try{var a=this;e._czc={push:function()
{return a.B.apply(a,arguments)}}}catch(b){g(b,"oP failed")}},aa:functi
on(){try{var a=e._czc;if("[object Array]"==={}.toString.call(a))for(va
r b=0;b<a.length;b ){var c=a[b];switch(c[0]){case "_setAccount":e.
_cz_account="[object String]"==={}.toString.call(c[1])?c[1]:String(c[1
]);.break;case "_setAutoPageview":"boolean"===typeof c[1]&&(e._cz_auto
Pageview=c[1])}}}catch(d){g(d,"cS failed")}},qa:function(){try{if("und
efined"===typeof e._cz_account||e._cz_account===this.c){e._cz_acco<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
`.rsrc
t$(SSh
|$D.tm
~%UVW
t.It It
u$SShe
shell32.dll
ntdll.dll
kernel32.dll
ole32.dll
ws2_32.dll
shlwapi.dll
user32.dll
advapi32.dll
msimg32.dll
MsgWaitForMultipleObjects
weburl
data\prguse.wis
data\prguse2.wis
data\prguse3.wis
tedlq.dll
xlq.txt
qwstart.exe
.text
`.data
.rsrc
C:\DistributedAutoLink\Temp\CompileOutputDir\i386\snetcfg.pdb
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
SETUPAPI.dll
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
hXXp://ocsp.verisign.com0
"hXXp://crl.verisign.com/tss-ca.crl0
Thawte Certification1
0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0
.Class 3 Public Primary Certification Authority0
2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.
hXXps://VVV.verisign.com/cps0*
hXXps://VVV.verisign.com/rpa0
#hXXp://logo.verisign.com/vslogo.gif0
hXXp://ocsp.verisign.com01
hXXp://crl.verisign.com/pca3.crl0)
DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
n.aAHu
3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
hXXp://ocsp.verisign.com0?
3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
!Game.ini
ServerPort=30471
LoginNo=15683
ServerAddr=127.0.0.1
ShowInitialMsg=1
xhelp.dll
.nR89
/%sC\
.bSEdTG
`w.Yw
8.KTQ
"n.hk3
cc{vpG%xMMj.Dh
x.uGS
}%sFW
cAN.pI7
_p\.mQe
.thE.u
.GKVLP@
iF%x,
.eqkT
R .Ft~
4F.XTs
aqfzb.exe
qD8Y%D
P.oJK
O3i
KH}{.pm.Vx.U
%.kQkn<
t.GSlMh
.LkLZa|
5[N.fY
%8x;-.N
_ 3 :.IG@1u.pY]Y%F<e*AHL0c.rrZ%StMlBløo.obqGVTd[%s-a.kse.k-G}hQjL%fiL."^xS%f<.ttJR_wm[.pZG>@.Jf9,@.LV@vYV.ySwn%FPo.RA(@.LV?yg%UWu-u.ueO[6/4N^.sDXBB@DW e%u~?*%u`D^.gB!)%D[BC1%FOJ1;C} ".rF.uyD;sqlDDd.UbD7.vQ_Hw.xE8wB%Us\O5.twrq>0%D\%X[\=:.aF9Lp9|*..SSUgssH6]:*.WZdW.Ao.sQ|~5%upB_.vr{w&y-2}.Vi)E.yds>7.qxfr%DG>8f%Ds5J.uA<ZA<%f~.QJ"rY*=,%S,\:y7%st.dQx%FqESI%dm[U0I.o.Jca9<3%x(=,-7}PU`.vS^6.RlvB?.GV9.Ov0C).YHg!N#.Im6<z.Usx.yRmW.ssRWum.afpt%Sr%Ch0ODyx%fUk%Ch0O.%Ch0Od-Be}W=%FyU%dN@i:vz%u[:f.Crc/$]*%dv%sc%XD9.WVW{*,.un}-E}gw9-J}JPkj.bgL.HBPC.gzmxw1Q%u@.mE=5||XbiÝI;Wy.lm(NL%DiV.WLfT:%xQ.kjDIKWV].xh.gEpsFJ)-VH}f{.OW\.syWTf:\-S.PBgZ.dlC) Z8M.PjK.pJ[N%N.PRjW5|bu.MjW;%dw|LQ(}%u..hv'v%uFC`I1qh>%dxq.TTNVM%FYoBh}GE.kd\xEÄN.XQqSJ.cQJ9%dmNH.rH7HTr:.ipM%U{kM.QD/xH-8}a}FSsh=.Lh@L.PI!1b~UM.XM-GÐT{um(1C.OP9.UUu.BF 9:1.Fo`.%X3.be:|0fP%F^ut{%X.4[(À.yjHO%DWP<5~%Ê0upH%SdW_%S 0FYp.sNtSQlWN.Ue/T7WR%cnmhftp.ePc}mMUdP%dv#'*@%%D]Sli*M.%snB.ne,\%UB|C~np%Se%dv#')%1u`I.OFu^D%S^m.oHxX;L8.EbH%uk:_,|.MZ63.bh\xp.qX1q(%x4ImWn.uq=tWn.uqb.My}p.WA|d.Uwb)%U;$x.UbmeÛrP[>.OkU\{.qCC%0u?.jj3%-L}FI%S(C#.fhJ8'X%UAWY=.Kfa',%cz=%F XcT\W.AFTn.Cjt}D.GE97gA.Cws%u)EKd.Ym3X.FV;=%s|5fSsh=#]%8XT.fd}>|%4Ug0.YJh%sX`kPÕrAU$%s|g:n%X {%F|=!FG]m7bÔVWHvJ%S:M;u.pQ%8.c~.Fn)g9.mKnf%CN5oOj7G1T.yF%snci_%XAb`.xCDQmHW[d.yjxF;1d%xg3%S<:E9=|*"{.vl}b5.Fl?.%c!$Z.Uk#T^\6.JvS#7..LH!DwzMj.FFFC%URr&7<.lleEF.aFm3`.Gp{.FF:n.ZjwA4"%2uEecMDe%dl5Z"7fc^-KY}qw:urLA.Wj`z'`.lD:ORH]-%FI#h.TUV.owns3[email protected]`9.wf3<H.sl8rL8.vCe6P~0A%CRv24%%u;.fou%C]Jh.PfTx"key`.ZO.hzlf;jtw%dD^-t}M%dKr.Wu/PW*.WEeZa%vM.yN-.obfR.yR*-]D%uO{_.xZ`Y.JA'k|~iX%fL.BxX.kp9qaNp/%S]4X4:.MCm6u.aS.cdh\CN@%D}#;5Ä3%p<.iy95@%XcKFq%u`,ZX.eCr0v.fw8v.xe@.dd@<aU:.fir)\zr*%xF_.Sb)LqR~.Rn{.QqkR.8.mLS=É)1W.gQ8%c&j6.VmBw,^6K%SVD9S.qh_G)a%cwj.Rk0`&6bX%CKpf~aabp;.lo~NÆB:.vL,e.zB-MYN<?sER.eNGOz%ufB.yhP?Chj.BI$y.ZPBO.HRwP%SPW>$"%c.DW>6z1.SG."Bsg%d|.Mdq~ca.YFdCrh].GsHfl.uLrqh%xk\{%Sk2.ZLa7.lV.dD_>l}C:.kp%=%x"FyD%Sf5"'P7.Sb%c/C*!.LwiSF.Oq?.LManM%dZ.tp?|vpv/-%Sg%x)hcD.JlKL_t.buVqQ.QS!.kI.F`%uHp%c"^X0#)?lZZQi^.YU!M.lzP{']%x2'5.AKI%X2#p|.Jv>.Ut>V%dG3Uaxqer.exeGLCore.dll287650928hXXp://zp.38kc.com/hXXp://pan.baidu.com/s/1i3HXSETinternetexplorer.application`.rdata@.data.reloc__MSVCRT_HEAP_SELECTUSER32.dllWS2_32.dllGetCPInfoCjDll.dllxxxxxxxxxxxxxxxx3 3$3(3,30343838!9)9/97977P7[7`7h70(3,30343hXXp://open.baidu.com/special/time/window.baidu_time(cq.dathXXp://hi.baidu.com/popplmplm2009/item/ad4bd800f53323c42e4c6b2aGameGuardurlmd5data\itemsas.wzlGameGuardurlY@downurlcxq.txt\!wjm.ini\DLQ.inidata\Prguse.wzldata\Prguse.wil\data\Prguse.wzl\data\Prguse.wiltkzz.txt\tkzz.txtlj.txtMemoryGuard.dll.kkp2pack.tmp[weburl]\user.iniupdateurl!wjm.ini\Map\0.map\map\0122.map\map\0150.map\map\11.mapMap\0.mapmap\0122.mapmap\0150.mapmap\11.map\data\DefaultBoss.dat[email protected].exe|.rar|.zip|.gif|.jpg|.mp3|.rmhXXp://jy.38kc.comAdobe Photoshop CS Windows2011:06:28 21:54:43urlTEXTMsgeTEXT0hXXp://ns.adobe.com/xap/1.0/<rdf:RDF xmlns:rdf='hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#' xmlns:iX='hXXp://ns.adobe.com/iX/1.0/'><rdf:Description rdf:about='uuid:193736f9-a18e-11e0-91f5-b945b6a58a8b'xmlns:exif='hXXp://ns.adobe.com/exif/1.0/'>xmlns:pdf='hXXp://ns.adobe.com/pdf/1.3/'>xmlns:photoshop='hXXp://ns.adobe.com/photoshop/1.0/'>xmlns:tiff='hXXp://ns.adobe.com/tiff/1.0/'>xmlns:xap='hXXp://ns.adobe.com/xap/1.0/'><xap:CreatorTool>Adobe Photoshop CS Windows</xap:CreatorTool>xmlns:stRef='hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#'xmlns:xapMM='hXXp://ns.adobe.com/xap/1.0/mm/'><stRef:instanceID>uuid:193736f5-a18e-11e0-91f5-b945b6a58a8b</stRef:instanceID><stRef:documentID>adobe:docid:photoshop:4717c0ba-47cf-11e0-8c96-bde67cf84c29</stRef:documentID><xapMM:DocumentID>adobe:docid:photoshop:193736f8-a18e-11e0-91f5-b945b6a58a8b</xapMM:DocumentID>xmlns:dc='hXXp://purl.org/dc/elements/1.1/'>IEC hXXp://VVV.iec.ch.IEC 61966-2.1 Default RGB colour space - sRGBCRT curv2011:06:28 21:55:072hXXp://ns.adobe.com/xap/1.0/<rdf:Description rdf:about='uuid:3b70805c-a18e-11e0-91f5-b945b6a58a8b'<stRef:instanceID>uuid:08f2867b-7fa2-11e0-9d22-f842cbbb5ea9</stRef:instanceID><xapMM:DocumentID>adobe:docid:photoshop:193736fe-a18e-11e0-91f5-b945b6a58a8b</xapMM:DocumentID>2013:12:15 18:46:01.fKf[[YhXXp://ns.adobe.com/xap/1.0/<rdf:Description rdf:about='uuid:e740154e-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:e740154d-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>ócnl5f?.sboih 38%DuQ]2013:12:15 18:39:21<rdf:Description rdf:about='uuid:b2dc8a02-6574-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:b2dc8a01-6574-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:40:18<rdf:Description rdf:about='uuid:4a35f139-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:4a35f138-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:41:20<rdf:Description rdf:about='uuid:4a35f141-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:4a35f140-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:42:00<rdf:Description rdf:about='uuid:6f7911d8-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:6f7911d7-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:42:29<rdf:Description rdf:about='uuid:6f7911dc-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:6f7911db-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>1%D>=2013:12:15 18:43:084.nv#<rdf:Description rdf:about='uuid:987d061f-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:987d061e-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:36:04<rdf:Description rdf:about='uuid:b2dc89fa-6574-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:9e0be246-6574-11e3-8b42-e5bd279358eb</xapMM:DocumentID>}%4SVOFd9vy.ll1911/01/012013:12:15 18:49:20.ifL:<rdf:Description rdf:about='uuid:865b8360-6576-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:865b835f-6576-11e3-8b42-e5bd279358eb</xapMM:DocumentID>w%d 52013:12:15 16:39:17<rdf:Description rdf:about='uuid:30a667dc-6564-11e3-adb6-920a1e92ee64'<xapMM:DocumentID>adobe:docid:photoshop:30a667db-6564-11e3-adb6-920a1e92ee64</xapMM:DocumentID>_.jZni9/%fO%UDNEV)7.KoI.LaB(*.*)|*.*inflate 1.1.3 Copyright 1995-1998 Mark AdlerF%*.*fCNotSupportedExceptioncommctrl_DragListMsgAfx:%x:%x:%x:%x:%xAfx:%x:%xCOMCTL32.DLLCCmdTargetSHLWAPI.dllMPR.dllVERSION.dll.PAVCException@@.PAVCNotSupportedException@@.PAVCFileException@@(*.prn)|*.prn|(*.*)|*.*||Shell32.dllMpr.dllAdvapi32.dllUser32.dllGdi32.dllKernel32.dll(&07-034/)7 '?? / %d]%d / %d]: %d](*.WAV;*.MID)|*.WAV;*.MID|WAV(*.WAV)|*.WAV|MIDI(*.MID)|*.MID|(*.txt)|*.txt|(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG(*.JPG)|*.JPG|BMP(*.BMP)|*.BMP|GIF(*.GIF)|*.GIF|(*.ICO)|*.ICO|(*.CUR)|*.CUR|%s:%dwindowsout.prn%d.%d%d / %d%d/%dBogus message code %d(%d-%d):%ld%c(*.htm;*.html)|*.htm;*.htmlits:%s::%sVVV.dywt.com.cnindex.datdesktop.inix86 Family %s Model %s Stepping %sX-X-X-XX-X-X-X-X-X[%s:%d]Range: bytes=%s-[%s:%d]PASS %sPASS ******USER %sE:\dev\e\static_link\static_libs\source\downlib\mystrlib.cppSIZE %sPORTUser-Agent: %sMozilla/4.0 (compatible; MSIE 5.00; Windows 98)Referer: %sHost: %sGET %s HTTP/1.1HTTP/1.0HTTP/1.1hXXp://Cookie: %s%d, %s\\192.168.0.129\TCP\1037NSPlayer/9.0.0.2980; {%s}; Host: %srmff_fix_header: assuming data.size=%irmff_fix_header: assuming data.num_packets=%irmff_fix_header: assuming prop.num_packets=%irmff_fix_header: setting prop.data_offset from %i to %irmff_fix_header: correcting prop.num_streams from %i to %irmff_fix_header: correcting prop.size from %i to %i%s %s %sSession: %sCseq: %u%*s %s%*s %uCSeq: %urtsp://%s:%irtsp://%s:%i/%sClientID: Linux_2.4_6.0.9.1235_play32_RN01_EN_586GUID: 00000000-0000-0000-0000-000000000000[%s:%d]User-Agent: RealMedia Player Version 6.0.9.1235 (linux-2.0-libc6-i386-gcc2.95)Range: npt=%s-%s/streamid=1%s/streamid=0Transport: x-pn-tng/tcp;mode=play,rtp/avp/tcp;unicast;mode=playIf-Match: %sRealChallenge2: %s, sd=%sTitle: %sCopyright: %sAuthor: %sreal: Content-length for description too big (> %uMB)!Require: com.real.retain-entity-for-setupSupportsMaximumASMBandwidth: 1Bandwidth: %uChallenge1: %shash output: %x %x %x %xhash input: %x %x %x %xstream=%u;rule=%u,Illegal character '%c' in input.1.1.3;3 #>6.&'2, / 0&7!4-)1#Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)%s <%s>Reply-To: %sFrom: %sTo: %sSubject: %sDate: %sCc: %s%a, %d %b %Y %H:%M:%SSMTPhXXp://dywt.com.cn[email protected]86(0411)8899583486(0411)88995831Windows(ESPINN.dll(NNThis is a runtime library file for EPL applications. The EPL is a software development environment. For details please visit VVV.dywt.com.cn/infoCallerInfoCopyCmdSetIPPortGetIPPort"C:\Windows\System32\ESPI11.dll"ProviderInstallCopyCmdSockDataCopyCmdSockAddrCopyCmdenetintercept_fnSockAddrSetIPPortenetintercept_fnSockAddrGetIPPortenetintercept_fnInstallCopyCmdenetintercept_fnSockDataCopyCmdenetintercept_fnSockAddrCopyCmdenetintercept_fnCallerInfoCopyCmd%s\ESPI%d.dll.PAVCOleException@@.PAVCObject@@.PAVCSimpleException@@.PAVCMemoryException@@.?AVCNotSupportedException@@.PAVCResourceException@@.PAVCUserException@@.?AVCCmdTarget@@.?AVCCmdUI@@.?AVCTestCmdUI@@.PAVCOleDispatchException@@.PAVCArchiveException@@zcÁc:\%original file name%.exeGetWindowsDirectoryAWinExecGetProcessHeapRegOpenKeyExARegDeleteKeyARegEnumKeyARegCreateKeyExARegOpenKeyARegCloseKeyGetViewportExtExGetViewportOrgExScaleViewportExtExSetViewportExtExOffsetViewportOrgExSetViewportOrgExShellExecuteAGetKeyStateSetWindowsHookExACreateDialogIndirectParamAUnhookWindowsHookExInternetCanonicalizeUrlAInternetCrackUrlAHttpOpenRequestAHttpSendRequestAHttpQueryInfoAFindFirstUrlCacheEntryAFindNextUrlCacheEntryADeleteUrlCacheEntry"bKeyaAOsH8k%CQeAUrlA3%Http#include "l.chs\afxres.rc" // Standard componentsKERNEL32.DLLCOMCTL32.dllcomdlg32.dllGDI32.dlliphlpapi.dllOLEAUT32.dlloledlg.dllRASAPI32.dllSHELL32.dllWININET.dllWINMM.dllWINSPOOL.DRVsnetcfg.exe26.0.0.255395668015625023456789(*.*)%original file name%.exe_1044_rwx_00401000_00849000:
t$(SSh|$D.tm~%UVWt.It Itu$SSheshell32.dllntdll.dllkernel32.dllole32.dllws2_32.dllshlwapi.dlluser32.dlladvapi32.dllmsimg32.dllMsgWaitForMultipleObjectsweburldata\prguse.wisdata\prguse2.wisdata\prguse3.wistedlq.dllxlq.txtqwstart.exe.text`.data.rsrcC:\DistributedAutoLink\Temp\CompileOutputDir\i386\snetcfg.pdbmsvcrt.dllADVAPI32.dllKERNEL32.dllSETUPAPI.dllversion="1.0.0.0"name="Microsoft.Windows.Common-Controls"version="6.0.0.0"publicKeyToken="6595b64144ccf1df"<requestedExecutionLevelhXXp://ocsp.verisign.com0"hXXp://crl.verisign.com/tss-ca.crl0Thawte Certification10hXXp://crl.verisign.com/ThawteTimestampingCA.crl0.Class 3 Public Primary Certification Authority02Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.hXXps://VVV.verisign.com/cps0*hXXps://VVV.verisign.com/rpa0#hXXp://logo.verisign.com/vslogo.gif0hXXp://ocsp.verisign.com01hXXp://crl.verisign.com/pca3.crl0)DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0n.aAHu3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0DhXXp://ocsp.verisign.com0?3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0!Game.iniServerPort=30471LoginNo=15683ServerAddr=127.0.0.1ShowInitialMsg=1xhelp.dll.nR89/%sC\.bSEdTG`w.Yw8.KTQ"n.hk3cc{vpG%xMMj.Dhx.uGS}%sFWcAN.pI7_p\.mQe.thE.u.GKVLP@iF%x,.eqkTR .Ft~4F.XTsaqfzb.exeqD8Y%DP.oJKO3iKH}{.pm.Vx.U%.kQkn<t.GSlMh.LkLZa|5[N.fY%8x;-.N_ 3 :.IG@1u.pY]Y%F<e*AHL0c.rrZ%StMlBløo.obqGVTd[%s-a.kse.k-G}hQjL%fiL."^xS%f<.ttJR_wm[.pZG>@.Jf9,@.LV@vYV.ySwn%FPo.RA(@.LV?yg%UWu-u.ueO[6/4N^.sDXBB@DW e%u~?*%u`D^.gB!)%D[BC1%FOJ1;C} ".rF.uyD;sqlDDd.UbD7.vQ_Hw.xE8wB%Us\O5.twrq>0%D\%X[\=:.aF9Lp9|*..SSUgssH6]:*.WZdW.Ao.sQ|~5%upB_.vr{w&y-2}.Vi)E.yds>7.qxfr%DG>8f%Ds5J.uA<ZA<%f~.QJ"rY*=,%S,\:y7%st.dQx%FqESI%dm[U0I.o.Jca9<3%x(=,-7}PU`.vS^6.RlvB?.GV9.Ov0C).YHg!N#.Im6<z.Usx.yRmW.ssRWum.afpt%Sr%Ch0ODyx%fUk%Ch0O.%Ch0Od-Be}W=%FyU%dN@i:vz%u[:f.Crc/$]*%dv%sc%XD9.WVW{*,.un}-E}gw9-J}JPkj.bgL.HBPC.gzmxw1Q%u@.mE=5||XbiÝI;Wy.lm(NL%DiV.WLfT:%xQ.kjDIKWV].xh.gEpsFJ)-VH}f{.OW\.syWTf:\-S.PBgZ.dlC) Z8M.PjK.pJ[N%N.PRjW5|bu.MjW;%dw|LQ(}%u..hv'v%uFC`I1qh>%dxq.TTNVM%FYoBh}GE.kd\xEÄN.XQqSJ.cQJ9%dmNH.rH7HTr:.ipM%U{kM.QD/xH-8}a}FSsh=.Lh@L.PI!1b~UM.XM-GÐT{um(1C.OP9.UUu.BF 9:1.Fo`.%X3.be:|0fP%F^ut{%X.4[(À.yjHO%DWP<5~%Ê0upH%SdW_%S 0FYp.sNtSQlWN.Ue/T7WR%cnmhftp.ePc}mMUdP%dv#'*@%%D]Sli*M.%snB.ne,\%UB|C~np%Se%dv#')%1u`I.OFu^D%S^m.oHxX;L8.EbH%uk:_,|.MZ63.bh\xp.qX1q(%x4ImWn.uq=tWn.uqb.My}p.WA|d.Uwb)%U;$x.UbmeÛrP[>.OkU\{.qCC%0u?.jj3%-L}FI%S(C#.fhJ8'X%UAWY=.Kfa',%cz=%F XcT\W.AFTn.Cjt}D.GE97gA.Cws%u)EKd.Ym3X.FV;=%s|5fSsh=#]%8XT.fd}>|%4Ug0.YJh%sX`kPÕrAU$%s|g:n%X {%F|=!FG]m7bÔVWHvJ%S:M;u.pQ%8.c~.Fn)g9.mKnf%CN5oOj7G1T.yF%snci_%XAb`.xCDQmHW[d.yjxF;1d%xg3%S<:E9=|*"{.vl}b5.Fl?.%c!$Z.Uk#T^\6.JvS#7..LH!DwzMj.FFFC%URr&7<.lleEF.aFm3`.Gp{.FF:n.ZjwA4"%2uEecMDe%dl5Z"7fc^-KY}qw:urLA.Wj`z'`.lD:ORH]-%FI#h.TUV.owns3[email protected]`9.wf3<H.sl8rL8.vCe6P~0A%CRv24%%u;.fou%C]Jh.PfTx"key`.ZO.hzlf;jtw%dD^-t}M%dKr.Wu/PW*.WEeZa%vM.yN-.obfR.yR*-]D%uO{_.xZ`Y.JA'k|~iX%fL.BxX.kp9qaNp/%S]4X4:.MCm6u.aS.cdh\CN@%D}#;5Ä3%p<.iy95@%XcKFq%u`,ZX.eCr0v.fw8v.xe@.dd@<aU:.fir)\zr*%xF_.Sb)LqR~.Rn{.QqkR.8.mLS=É)1W.gQ8%c&j6.VmBw,^6K%SVD9S.qh_G)a%cwj.Rk0`&6bX%CKpf~aabp;.lo~NÆB:.vL,e.zB-MYN<?sER.eNGOz%ufB.yhP?Chj.BI$y.ZPBO.HRwP%SPW>$"%c.DW>6z1.SG."Bsg%d|.Mdq~ca.YFdCrh].GsHfl.uLrqh%xk\{%Sk2.ZLa7.lV.dD_>l}C:.kp%=%x"FyD%Sf5"'P7.Sb%c/C*!.LwiSF.Oq?.LManM%dZ.tp?|vpv/-%Sg%x)hcD.JlKL_t.buVqQ.QS!.kI.F`%uHp%c"^X0#)?lZZQi^.YU!M.lzP{']%x2'5.AKI%X2#p|.Jv>.Ut>V%dG3Uaxqer.exeGLCore.dll287650928hXXp://zp.38kc.com/hXXp://pan.baidu.com/s/1i3HXSETinternetexplorer.application`.rdata@.data.reloc__MSVCRT_HEAP_SELECTUSER32.dllWS2_32.dllGetCPInfoCjDll.dllxxxxxxxxxxxxxxxx3 3$3(3,30343838!9)9/97977P7[7`7h70(3,30343hXXp://open.baidu.com/special/time/window.baidu_time(cq.dathXXp://hi.baidu.com/popplmplm2009/item/ad4bd800f53323c42e4c6b2aGameGuardurlmd5data\itemsas.wzlGameGuardurlY@downurlcxq.txt\!wjm.ini\DLQ.inidata\Prguse.wzldata\Prguse.wil\data\Prguse.wzl\data\Prguse.wiltkzz.txt\tkzz.txtlj.txtMemoryGuard.dll.kkp2pack.tmp[weburl]\user.iniupdateurl!wjm.ini\Map\0.map\map\0122.map\map\0150.map\map\11.mapMap\0.mapmap\0122.mapmap\0150.mapmap\11.map\data\DefaultBoss.dat[email protected].exe|.rar|.zip|.gif|.jpg|.mp3|.rmhXXp://jy.38kc.comAdobe Photoshop CS Windows2011:06:28 21:54:43urlTEXTMsgeTEXT0hXXp://ns.adobe.com/xap/1.0/<rdf:RDF xmlns:rdf='hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#' xmlns:iX='hXXp://ns.adobe.com/iX/1.0/'><rdf:Description rdf:about='uuid:193736f9-a18e-11e0-91f5-b945b6a58a8b'xmlns:exif='hXXp://ns.adobe.com/exif/1.0/'>xmlns:pdf='hXXp://ns.adobe.com/pdf/1.3/'>xmlns:photoshop='hXXp://ns.adobe.com/photoshop/1.0/'>xmlns:tiff='hXXp://ns.adobe.com/tiff/1.0/'>xmlns:xap='hXXp://ns.adobe.com/xap/1.0/'><xap:CreatorTool>Adobe Photoshop CS Windows</xap:CreatorTool>xmlns:stRef='hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#'xmlns:xapMM='hXXp://ns.adobe.com/xap/1.0/mm/'><stRef:instanceID>uuid:193736f5-a18e-11e0-91f5-b945b6a58a8b</stRef:instanceID><stRef:documentID>adobe:docid:photoshop:4717c0ba-47cf-11e0-8c96-bde67cf84c29</stRef:documentID><xapMM:DocumentID>adobe:docid:photoshop:193736f8-a18e-11e0-91f5-b945b6a58a8b</xapMM:DocumentID>xmlns:dc='hXXp://purl.org/dc/elements/1.1/'>IEC hXXp://VVV.iec.ch.IEC 61966-2.1 Default RGB colour space - sRGBCRT curv2011:06:28 21:55:072hXXp://ns.adobe.com/xap/1.0/<rdf:Description rdf:about='uuid:3b70805c-a18e-11e0-91f5-b945b6a58a8b'<stRef:instanceID>uuid:08f2867b-7fa2-11e0-9d22-f842cbbb5ea9</stRef:instanceID><xapMM:DocumentID>adobe:docid:photoshop:193736fe-a18e-11e0-91f5-b945b6a58a8b</xapMM:DocumentID>2013:12:15 18:46:01.fKf[[YhXXp://ns.adobe.com/xap/1.0/<rdf:Description rdf:about='uuid:e740154e-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:e740154d-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>ócnl5f?.sboih 38%DuQ]2013:12:15 18:39:21<rdf:Description rdf:about='uuid:b2dc8a02-6574-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:b2dc8a01-6574-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:40:18<rdf:Description rdf:about='uuid:4a35f139-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:4a35f138-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:41:20<rdf:Description rdf:about='uuid:4a35f141-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:4a35f140-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:42:00<rdf:Description rdf:about='uuid:6f7911d8-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:6f7911d7-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:42:29<rdf:Description rdf:about='uuid:6f7911dc-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:6f7911db-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>1%D>=2013:12:15 18:43:084.nv#<rdf:Description rdf:about='uuid:987d061f-6575-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:987d061e-6575-11e3-8b42-e5bd279358eb</xapMM:DocumentID>2013:12:15 18:36:04<rdf:Description rdf:about='uuid:b2dc89fa-6574-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:9e0be246-6574-11e3-8b42-e5bd279358eb</xapMM:DocumentID>}%4SVOFd9vy.ll1911/01/012013:12:15 18:49:20.ifL:<rdf:Description rdf:about='uuid:865b8360-6576-11e3-8b42-e5bd279358eb'<xapMM:DocumentID>adobe:docid:photoshop:865b835f-6576-11e3-8b42-e5bd279358eb</xapMM:DocumentID>w%d 52013:12:15 16:39:17<rdf:Description rdf:about='uuid:30a667dc-6564-11e3-adb6-920a1e92ee64'<xapMM:DocumentID>adobe:docid:photoshop:30a667db-6564-11e3-adb6-920a1e92ee64</xapMM:DocumentID>_.jZni9/%fO%UDNEV)7.KoI.LaB(*.*)|*.*inflate 1.1.3 Copyright 1995-1998 Mark AdlerF%*.*fCNotSupportedExceptioncommctrl_DragListMsgAfx:%x:%x:%x:%x:%xAfx:%x:%xCOMCTL32.DLLCCmdTargetSHLWAPI.dllMPR.dllVERSION.dll.PAVCException@@.PAVCNotSupportedException@@.PAVCFileException@@(*.prn)|*.prn|(*.*)|*.*||Shell32.dllMpr.dllAdvapi32.dllUser32.dllGdi32.dllKernel32.dll(&07-034/)7 '?? / %d]%d / %d]: %d](*.WAV;*.MID)|*.WAV;*.MID|WAV(*.WAV)|*.WAV|MIDI(*.MID)|*.MID|(*.txt)|*.txt|(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG(*.JPG)|*.JPG|BMP(*.BMP)|*.BMP|GIF(*.GIF)|*.GIF|(*.ICO)|*.ICO|(*.CUR)|*.CUR|%s:%dwindowsout.prn%d.%d%d / %d%d/%dBogus message code %d(%d-%d):%ld%c(*.htm;*.html)|*.htm;*.htmlits:%s::%sVVV.dywt.com.cnindex.datdesktop.inix86 Family %s Model %s Stepping %sX-X-X-XX-X-X-X-X-X[%s:%d]Range: bytes=%s-[%s:%d]PASS %sPASS ******USER %sE:\dev\e\static_link\static_libs\source\downlib\mystrlib.cppSIZE %sPORTUser-Agent: %sMozilla/4.0 (compatible; MSIE 5.00; Windows 98)Referer: %sHost: %sGET %s HTTP/1.1HTTP/1.0HTTP/1.1hXXp://Cookie: %s%d, %s\\192.168.0.129\TCP\1037NSPlayer/9.0.0.2980; {%s}; Host: %srmff_fix_header: assuming data.size=%irmff_fix_header: assuming data.num_packets=%irmff_fix_header: assuming prop.num_packets=%irmff_fix_header: setting prop.data_offset from %i to %irmff_fix_header: correcting prop.num_streams from %i to %irmff_fix_header: correcting prop.size from %i to %i%s %s %sSession: %sCseq: %u%*s %s%*s %uCSeq: %urtsp://%s:%irtsp://%s:%i/%sClientID: Linux_2.4_6.0.9.1235_play32_RN01_EN_586GUID: 00000000-0000-0000-0000-000000000000[%s:%d]User-Agent: RealMedia Player Version 6.0.9.1235 (linux-2.0-libc6-i386-gcc2.95)Range: npt=%s-%s/streamid=1%s/streamid=0Transport: x-pn-tng/tcp;mode=play,rtp/avp/tcp;unicast;mode=playIf-Match: %sRealChallenge2: %s, sd=%sTitle: %sCopyright: %sAuthor: %sreal: Content-length for description too big (> %uMB)!Require: com.real.retain-entity-for-setupSupportsMaximumASMBandwidth: 1Bandwidth: %uChallenge1: %shash output: %x %x %x %xhash input: %x %x %x %xstream=%u;rule=%u,Illegal character '%c' in input.1.1.3;3 #>6.&'2, / 0&7!4-)1#Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)%s <%s>Reply-To: %sFrom: %sTo: %sSubject: %sDate: %sCc: %s%a, %d %b %Y %H:%M:%SSMTPhXXp://dywt.com.cn[email protected]86(0411)8899583486(0411)88995831Windows(ESPINN.dll(NNThis is a runtime library file for EPL applications. The EPL is a software development environment. For details please visit VVV.dywt.com.cn/infoCallerInfoCopyCmdSetIPPortGetIPPort"C:\Windows\System32\ESPI11.dll"ProviderInstallCopyCmdSockDataCopyCmdSockAddrCopyCmdenetintercept_fnSockAddrSetIPPortenetintercept_fnSockAddrGetIPPortenetintercept_fnInstallCopyCmdenetintercept_fnSockDataCopyCmdenetintercept_fnSockAddrCopyCmdenetintercept_fnCallerInfoCopyCmd%s\ESPI%d.dll.PAVCOleException@@.PAVCObject@@.PAVCSimpleException@@.PAVCMemoryException@@.?AVCNotSupportedException@@.PAVCResourceException@@.PAVCUserException@@.?AVCCmdTarget@@.?AVCCmdUI@@.?AVCTestCmdUI@@.PAVCOleDispatchException@@.PAVCArchiveException@@zcÁc:\%original file name%.exeGetWindowsDirectoryAWinExecGetProcessHeapRegOpenKeyExARegDeleteKeyARegEnumKeyARegCreateKeyExARegOpenKeyARegCloseKeyGetViewportExtExGetViewportOrgExScaleViewportExtExSetViewportExtExOffsetViewportOrgExSetViewportOrgExShellExecuteAGetKeyStateSetWindowsHookExACreateDialogIndirectParamAUnhookWindowsHookExInternetCanonicalizeUrlAInternetCrackUrlAHttpOpenRequestAHttpSendRequestAHttpQueryInfoAFindFirstUrlCacheEntryAFindNextUrlCacheEntryADeleteUrlCacheEntry"bKeyaAOsH8k%CQeAUrlA3%Httpsnetcfg.exe26.0.0.255395668015625023456789
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TPHNX2CD\core[1].php (751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WH6BWP6F\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W1IFKDIZ\z_stat[1].php (1097 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5PN7CW2U\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W1IFKDIZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.°´ÃÂÂüƬ.tmp (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷¹«¸æ.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WH6BWP6F\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\9d47568b311bab588769ba0807e9bfd2.ini (381 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¿Ã·þÖÃÂÃÂÄ.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥µÇ½ÓÎ÷.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂ˳öÓÎ÷.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TPHNX2CD\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ø±Õ.µãȼüƬ.tmp (824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5PN7CW2U\jy.38kc[1].htm (359 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×°±¸½éÉÜ.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.µãȼüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×îữ.Õý³£Ã¼Ƭ.tmp (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÓÎ÷ÂÛ̳.°´ÃÂÂüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥Ã½¨Õ˺Å.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥×îữ.µãȼüƬ.tmp (824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÕÒ»ØÃÜÂë.Õý³£Ã¼Ƭ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\µ×ü.tmp (189 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂà¹ØÃÂÂÃâ€ÃƒËœ.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\DLQ.ini (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ù·½Ö÷Ò³.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\pack.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.Õý³£Ã¼Ƭ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂÞ¸ÄÃÜÂë.°´ÃÂÂüƬ.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥ÃÂæ¼ÒÕÕÆ¬.µãȼüƬ.tmp (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\9d47568b311bab588769ba0807e9bfd2\°´Å¥¹Ø±Õ.Õý³£Ã¼Ƭ.tmp (14 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.