Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\HappyHeros_SetInfo.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\server[1].txt
- <SYSTEM32>\xbl_server.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\server[1].txt
- 'www.ba##u.com':80
- '18#.#0.161.188':0
- 'www.cs##ub.com':80
- www.ba##u.com/s?wd###############
- www.cs##ub.com/member/server.txt
- DNS ASK www.ba##u.com
- DNS ASK www.cs##ub.com
- '18#.#0.161.188':0
- ClassName: 'Shell_TrayWnd' WindowName: ''