Technical Information
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\fc700.tmp
- %TEMP%\fc79d.tmp
- %TEMP%\fc7dd.tmp
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020042220200423\index.dat
- %TEMP%\fc700.tmp
- %TEMP%\fc79d.tmp
- %TEMP%\fc7dd.tmp
- http://www.mo##nyy.cn/cansu521.txt
- DNS ASK mo##nyy.cn
- DNS ASK ba##u.com
- ClassName: 'ENewFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\svchost.exe'