Technical Information
- '<SYSTEM32>\rundll32.exe' 8sSJnJ.dll,load qChsB.dll
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\qChsB.dll
- %TEMP%\Version.txt
- <SYSTEM32>\8sSJnJ.dll
- <SYSTEM32>\Uy6gQsqB.dll
- <SYSTEM32>\pmonitor.tmp
- <SYSTEM32>\pmonitor.tmp
- %TEMP%\Version.txt
- '<Private IP address>':53
- 'cl###.rtmedia.cn':80
- '12#.#25.114.144':80
- 'cn##n.com':80
- 'ba###bar.info':80
- cn##n.com/6lV4
- 12#.#25.114.144/ecom?di##################################################################
- cl###.rtmedia.cn/d.aspx
- cn##n.com/QmS4
- ba###bar.info/rtbho.xml
- cn##n.com/pTg4
- DNS ASK cl###.rtmedia.cn
- DNS ASK cb.##idu.com
- DNS ASK cn##n.com
- DNS ASK ba###bar.info
- '25#.#55.255.255':32336
- ClassName: 'Progman' WindowName: 'Program Manager'