0 Members and 1 Guest are viewing this topic.
www.chliyi.com/reg.js (iframe injected) www.chliyi.com/img/info.htm (vbscript obfustication) www.chliyi.com/img/real.htm (exploit) www.chliyi.com/img/new.htm (exploit) www.chliyi.com/img/help.htm (exploit) www.jj120.net/inc/fuckjp.exe (bin from exploits) www.hanme.cn/chs/faq/WLoader.exe (gets this after above bin executes) www.hanme.cn/chs/faq/FLoader.exe (and then gets this)