Technical Information
- ClassName: 'TXGuiFoundation', WindowName: '???????? - ????????????'
- ClassName: 'TXGuiFoundation', WindowName: 'µзДФ№ЬјТ - НшВзБчБї№ЬАн'
- <Current directory>\МбИЎ№¤ѕЯ.exe
- %APPDATA%\Microsoft\Media Player\npiaa\VBS.vbs
- <Current directory>\МбИЎ№¤ѕЯ.exe
- %APPDATA%\Microsoft\Media Player\npiaa\svohost.exe
- %APPDATA%\Microsoft\Media Player\npiaa\VBS.vbs
- from <Full path to file> to %APPDATA%\Microsoft\Media Player\npiaa\svohost.exe
- '47.##.127.204':33
- '12#.#25.114.144':80
- 'jw###.msns.cn':49596
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK www.ba##u.com
- DNS ASK jw###.msns.cn
- '<Current directory>\МбИЎ№¤ѕЯ.exe'
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Microsoft\Media Player\npiaa\VBS.vbs"