Technical Information
- <SYSTEM32>\taskhost.exe
- iexplore.exe
- %PROGRAMDATA%\xi\lqxfet.sre
- %TEMP%\ddaad.aux
- '66.##0.23.114':80
- http://ca###zine.com/jki.php?uu########################################################
- DNS ASK microsoft.com
- DNS ASK hk###rrk.com
- DNS ASK vg##v.com
- '<SYSTEM32>\rundll32.exe' -f wfwly.dll