Technical Information
- '<SYSTEM32>\systems.exe'
- '%TEMP%\is-1IADR.tmp\lantiankeji.tmp' /SL5="$100F0,602368,72704,<SYSTEM32>\lantiankeji.EXE"
- '<SYSTEM32>\lantiankeji.EXE'
- '<SYSTEM32>\systems.exe' (downloaded from the Internet)
- %TEMP%\is-2U16E.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\systems[1].exe
- <SYSTEM32>\systems.exe
- <SYSTEM32>\lantiankeji.EXE
- %TEMP%\is-1IADR.tmp\lantiankeji.tmp
- %TEMP%\is-2U16E.tmp\_isetup\_RegDLL.tmp
- 'www.cn##aa.cn':80
- 'localhost':1035
- www.cn##aa.cn/soft/systems.exe
- DNS ASK www.cn##aa.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'