Technical Information
- %TEMP%\vbusup\notese001.txt D "<Full path to virus>" CoUi
- %TEMP%\vbusup\setup.exe
- %TEMP%\vbusup\ssinitar.exe -pasdfghij -d"%TEMP%\vbusup\"
- <SYSTEM32>\cmd.exe /c .\qelivene1.bat
- %TEMP%\vbusup\notese001.txt
- <Current directory>\qelivene1.bat
- %TEMP%\vbusup\ssinitar.exe
- %TEMP%\vbusup\setup.exe
- %TEMP%\vbusup\notese001.txt
- %TEMP%\vbusup\setup.exe
- %TEMP%\vbusup\ssinitar.exe
- 'co###.llads.cn':80
- co###.llads.cn/chk/login.asp
- DNS ASK co###.llads.cn
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''