Technical Information
- [HKLM\SOFTWARE\Wow6432Node\MicroSoft\Windows\CurrentVersion\Run] '×ÊÔ´¹ÜÀГÆ÷' = 'c:\\Program Files\\Program Files\\explore.exe'
- %ProgramFiles%\program files\explore.exe
- 'nn##n.com':80
- http://www.nn##n.com/bho.html
- DNS ASK nn##n.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''