Technical Information
- D:\zsjhw\×ê꯼滮Гõ³ìðòéý¼¶¹üà Гæ÷.exe
- D:\zsjhw\.tmp
- <Current directory>\wery.exe
- D:\zsjhw\.tmp
- from <Full path to file> to <Current directory>\¾é°æ±¾<File name>.exe
- http://bb#.uc.cn/home.php?mo##################
- http://11#.#9.87.115/uploads/soft/guajiwang.xml
- http://11#.#9.87.115/uploads/soft/huangj.exe
- DNS ASK bb#.uc.cn
- DNS ASK bo###000.com
- ClassName: '' WindowName: 'ÐÅŵȫ×Ô¶¯¹Ò»úϵͳ.exe'
- ClassName: '' WindowName: '<File name>.exe'
- ClassName: '' WindowName: 'wery.exe'
- 'D:\zsjhw\×ê꯼滮Гõ³ìðòéý¼¶¹üà Гæ÷.exe' http://11#.#9.87.115/uploads/soft/huangj.exe d:\zsjhw wery.exe <Full path to file>
- '<Current directory>\wery.exe'