Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'name' = '%ProgramFiles(x86)%\Tencent\TXPlatform.exe'
- Windows Update
- %WINDIR%\lany.dll
- %WINDIR%\lany.dll
- '43.##2.162.5':80
- '43.##2.162.5':7438
- http://43.##2.162.5/lany.dll
- '43.##2.162.5':7438
- '%WINDIR%\syswow64\cmd.exe' /c color 6