最新木马C:\00002E24\196343
00002E24好像是随硬件的什么序列号生成的
196343文件里的代码为:
36
http://bally1.bally-bally.net/laco1.exe
http://bally1.bally-bally.net/laco2.exe
http://bally1.bally-bally.net/laco3.exe
http://bally1.bally-bally.net/laco4.exe
http://bally1.bally-bally.net/laco5.exe
http://bally1.bally-bally.net/laco6.exe
http://bally1.bally-bally.net/laco7.exe
http://bally2.bally-bally.net/laco9.exe
http://bally2.bally-bally.net/laco10.exe
http://bally2.bally-bally.net/laco11.exe
http://bally2.bally-bally.net/laco12.exe
http://bally2.bally-bally.net/laco13.exe
http://bally2.bally-bally.net/laco14.exe
http://bally2.bally-bally.net/laco15.exe
http://bally2.bally-bally.net/laco16.exe
http://bally2.bally-bally.net/laco17.exe
http://bally2.bally-bally.net/laco18.exe
http://bally2.bally-bally.net/laco19.exe
http://bally2.bally-bally.net/laco20.exe
http://bally2.bally-bally.net/laco21.exe
http://bally2.bally-bally.net/laco22.exe
http://bally2.bally-bally.net/laco23.exe
http://bally2.bally-bally.net/laco24.exe
http://bally2.bally-bally.net/laco25.exe
http://bally2.bally-bally.net/laco26.exe
http://bally2.bally-bally.net/laco27.exe
http://bally2.bally-bally.net/laco28.exe
http://bally2.bally-bally.net/laco29.exe
http://bally2.bally-bally.net/laco30.exe
http://bally2.bally-bally.net/laco31.exe
http://bally2.bally-bally.net/laco32.exe
http://bally2.bally-bally.net/laco33.exe
http://bally2.bally-bally.net/laco34.exe
http://bally2.bally-bally.net/laco35.exe
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)