Technical Information
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://do##.###up-down.com:8080/alltj.html?up####
- %TEMP%\nsy5.tmp
- %TEMP%\uninst.exe
- %TEMP%\nsb7.tmp
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsj3.tmp\InetLoad.dll
- %TEMP%\nse2.tmp
- %TEMP%\temp.ini
- %TEMP%\nsj3.tmp\System.dll
- <Full path to file>
- %TEMP%\temp.ini
- %TEMP%\uninst.exe
- %TEMP%\nsj3.tmp\InetLoad.dll
- %TEMP%\nsj3.tmp\System.dll
- 'do##.#etup-down.com':8080
- 'localhost':1040
- 'dd##.#etup-down.com':8080
- DNS ASK do##.#etup-down.com
- DNS ASK dd##.#etup-down.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\~nsu.tmp\Au_.exe' _?=%TEMP%\
- '%TEMP%\uninst.exe'