Technical Information
- '' (downloaded from the Internet)
- %TEMP%\nsr5226.tmp
- %TEMP%\nsg5236.tmp\system.dll
- %TEMP%\1.ico
- %TEMP%\rav3490022.exe
- http://ce####.rising.com.cn/urg.asp?v=################
- http://w.#.#aidu.com/go/mini/201/1202000632
- http://mi##.wcd.qq.com/app?pa#####################################
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://do##2.uc.cn/pcbrowser/down.php?pi######
- http://rs####.rising.com.cn/register/minicenter/e/c.aspx
- DNS ASK f.##236.com
- DNS ASK w.#.#aidu.com
- DNS ASK ce####.rising.com.cn
- DNS ASK cd#.#unshark.cn
- DNS ASK rs####.rising.com.cn
- DNS ASK mi##.wcd.qq.com
- DNS ASK microsoft.com
- DNS ASK so##.#ymcanal.com
- DNS ASK do##2.uc.cn
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\rav3490022.exe'