Technical Information
- "%TEMP%\360.exe" (downloaded from the Internet)
- %TEMP%\360.exe.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\sort[1].php
- <Current directory>\SkinH_EL.dll
- <Current directory>\SkinH_EL.dll
- '12#.#24.11.83':80
- 'www.qq##.com':80
- 'localhost':1036
- 12#.#24.11.83/a.exe
- www.qq##.com/sort.php
- DNS ASK www.qq##.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''