Technical Information
- ClassName: 'Filemonclass' WindowName: ''
- ClassName: 'Regmonclass' WindowName: ''
- <SYSTEM32>\superecb29ll.sys
- %TEMP%\SE1.tmp
- <SYSTEM32>\superecb29ll.sys
- %TEMP%\SE1.tmp
- 'www.26##.com':80
- 'www.ba##u.com':80
- 'www.39##g.com':80
- 'localhost':1035
- 'www.cf###shi.net':80
- www.ba##u.com/s?wd#############
- www.26##.com/yz.txt
- www.cf###shi.net/
- DNS ASK www.26##.com
- DNS ASK www.ba##u.com
- DNS ASK www.39##g.com
- DNS ASK www.cf###shi.net
- '<Private IP address>':1038
- '<Private IP address>':1036
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''