Technical Information
- %WINDIR%\regedit.exe /s "%CommonProgramFiles%\tk.reg"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\data[1].txt
- C:\about blank.htm
- %PROGRAM_FILES%\winrar\gwdaizbtx.uqrne
- %WINDIR%\My.ini
- %CommonProgramFiles%\tk.reg
- C:\about blank.htm
- %PROGRAM_FILES%\winrar\gwdaizbtx.uqrne
- %CommonProgramFiles%\tk.reg
- 'up.##36688.com':80
- 'localhost':1037
- up.##36688.com/ip.asp
- up.##36688.com/data.txt
- DNS ASK up.##36688.com
- '<Private IP address>':1038
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''