Technical Information
- NtQuerySystemInformation, handler: jinfuhide.dat
- <Full path to virus>
- <Current directory>\com.run
- <Current directory>\krnln.fnr
- C:\zzjb\±»»ч°Ь.bmp
- <Current directory>\zzdx.dll
- <Current directory>\Ѕ»ёшДгАІ.wav
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\176bb92f61649d5dac34deff[1].html
- <Current directory>\spec.fne
- <Current directory>\TKGS.dll
- <Current directory>\jinfuhide.dat
- C:\zzjb\zzdx.dll
- <Current directory>\Hook.dll
- C:\kissme
- C:\zzjb\ЅбКшesc.bmp
- C:\zzjb\СйЦ¤dm.bmp
- C:\zzjb\їЄКј.bmp
- C:\zzjb\ЧўТв.bmp
- <Current directory>\jinfuhide.dat
- C:\kissme
- <Current directory>\Hook.dll
- <Current directory>\jinfuhide.dat
- '12#.#25.114.144':80
- 12#.#25.114.144/mingmx/blog/item/176bb92f61649d5dac34deff.html
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'