Technical Information
- <SYSTEM32>\EnvoEml.exe (downloaded from the Internet)
- <SYSTEM32>\BTStacAvs.exe (downloaded from the Internet)
- <SYSTEM32>\MsgrUpd.exe (downloaded from the Internet)
- <SYSTEM32>\BTStacLrj.exe (downloaded from the Internet)
- <SYSTEM32>\BTStacFrr.exe (downloaded from the Internet)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\zzamsn2[1].mp3
- <SYSTEM32>\MsgrUpd.exe
- <SYSTEM32>\EnvoEml.exe
- <SYSTEM32>\BTStacAvs.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zzahavs[1].mp3
- <SYSTEM32>\BTStacLrj.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zzahlrj[1].mp3
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\zzahfrr[1].mp3
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\zzahmsn[1].mp3
- <SYSTEM32>\BTStacFrr.exe
- 'www.qu###oking.com':80
- 'localhost':1035
- www.qu###oking.com/mstr/zzamsn2.mp3
- www.qu###oking.com/mstr/zzahavs.mp3
- www.qu###oking.com/mstr/zzahmsn.mp3
- www.qu###oking.com/mstr/zzahlrj.mp3
- www.qu###oking.com/mstr/zzahfrr.mp3
- DNS ASK www.qu###oking.com
- '<Private IP address>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''