Technical Information
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://tj###8.3322.org/tj/tongji.php?ve###################
- <SYSTEM32>\taskkill.exe /f /im 99Lover.exe
- <Current directory>\One.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongji[1].php
- <Current directory>\Hook.dll
- 'localhost':1040
- 'tj###8.3322.org':80
- '21#.#0.65.168':88
- 'localhost':1037
- tj###8.3322.org/tj/tongji.php?ve###################
- DNS ASK tj###8.3322.org
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''