Technical Information
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.59##ule.com
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\guangao[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\592yule[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\592yule[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\shuoming[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\daoh[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\592yule[1]
- 'www.59##ule.com':80
- 'localhost':1042
- 'localhost':1037
- 'hi.##idu.com':80
- www.59##ule.com/
- www.59##ule.com/guangao
- www.59##ule.com/daoh
- hi.##idu.com/%C3%D4%C2%B7%C3%E6%B0%FC/blog/item/94012fa0ebd1d1134a36d63f.html
- www.59##ule.com/shuoming.txt
- DNS ASK www.59##ule.com
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''