Technical Information
- '%WINDIR%\setup-hall-main.exe'
- '%WINDIR%\NtnLpmj.exe'
- %TEMP%\nsl3.tmp\ioSpecial.ini
- %PROGRAM_FILES%\BaoFeng\StormPlayer.exe
- %TEMP%\nsl3.tmp\modern-wizard.bmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ips138[1].asp
- %TEMP%\nsl3.tmp\InstallOptions.dll
- %TEMP%\nsl3.tmp\System.dll
- %WINDIR%\setup-hall-main.exe
- %WINDIR%\NtnLpmj.exe
- %PROGRAM_FILES%\BaoFeng\StormPlayer.dll
- %TEMP%\nsl3.tmp\nsProcess.dll
- %TEMP%\nsb2.tmp
- 'yk.##eaxzvc.com':8098
- 'www.ip##8.com':80
- 'xz.##eaxzvc.com':9301
- www.ip##8.com/ips138.asp?ip################
- DNS ASK yk.##eaxzvc.com
- DNS ASK www.ip##8.com
- DNS ASK xz.##eaxzvc.com
- ClassName: '' WindowName: '???????? ?? ????'
- ClassName: '' WindowName: '????????'
- ClassName: 'kxetray' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''