Technical Information
- <Current directory>\zv.exe
- <Current directory>\iw.exe
- %WINDIR%\fonts\226.dll
- from <Current directory>\zv.exe to %TEMP%\1297007\....\temporaryfile
- from <Full path to file> to %TEMP%\1293076\....\temporaryfile
- 'bx#####120036.my3w.com':80
- http://bx#####120036.my3w.com/cjzs.html
- DNS ASK bx#####120036.my3w.com
- '<Current directory>\zv.exe'
- '%WINDIR%\syswow64\rundll32.exe' url.dll,FileProtocolHandler