Technical Information
- '<Full path to file>' (downloaded from the Internet)
- '<Full path to file>'
- '<SYSTEM32>\cmd.exe' /c "<Current directory>\ .bat"
- <Current directory>\ .bat
- <Current directory>\1.exe.tmp
- 'localhost':1041
- 'up####.5168fx.com':80
- http://up####.5168fx.com/plugin/taobaoke/%E5%85%A8%E6%B0%91%E6%B7%98%E5%AE%9D%E5%AE%A2_%E5%8A%A9%E6%89%8B.exe
- http://up####.5168fx.com/plugin/taobaoke/banben.txt
- DNS ASK m.###8fx.com
- DNS ASK up####.5168fx.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''