Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<Current directory>\Sysceamgucma.exe'
- <Current directory>\cpath.ini
- <Current directory>\syscaemgucma.exe
- <Current directory>\sysceamgucma.exe
- <Current directory>\c1.dat
- <Current directory>\c2.dat
- <Current directory>\sysceamgucma.exe
- <Current directory>\c1.dat
- <Current directory>\c2.dat
- DNS ASK ui.###ogin2.qq.com
- DNS ASK ss#.##login2.qq.com
- DNS ASK i3.##etuku.com
- '<Current directory>\sysceamgucma.exe'