Technical Information
- '%WINDIR%\GuaGua2010Beta2SetupGW_tg.exe'
- '%WINDIR%\654.exe'
- '%WINDIR%\GuaGua2010Beta2SetupGW_tg.exe' (downloaded from the Internet)
- '%WINDIR%\654.exe' (downloaded from the Internet)
- '<SYSTEM32>\taskkill.exe' /f /im ChatHall.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\CA7ESJZ1.jsp
- %WINDIR%\654.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\reg_page[1].jsp
- %WINDIR%\GuaGua2010Beta2SetupGW_tg.exe
- 'www.gu###a.com.cn':80
- 'localhost':1037
- 'www.ai##awd.com':80
- www.gu###a.com.cn/interface/reg_page.jsp?ad#############################################################################################
- www.ai##awd.com/qixi/guagua.php
- DNS ASK www.gu###a.com.cn
- DNS ASK www.ai##awd.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'