Technical Information
- <SYSTEM32>\msiexec.exe /i "<LS_APPDATA>\hta.txt" /quiet
- <SYSTEM32>\msiexec.exe /V
- <SYSTEM32>\mshta.exe vbscript:createobject("wscript.shell").run("""iexplore""http://cn##.sjt8.com/info.access/?st###########",0)(window.close)
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://cn##.sjt8.com/info.access/?st###########
- <LS_APPDATA>\Client.ini
- <LS_APPDATA>\yClient.ini
- <LS_APPDATA>\hta.txt
- <LS_APPDATA>\sta.txt
- <LS_APPDATA>\kInstall.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\dClient.ini
- <LS_APPDATA>\sqlite3.txt
- %TEMP%\~1.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''