Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\TrkWks] 'Start' = '00000002'
- '%TEMP%\RarSFX0\Explorer.exe'
- '<SYSTEM32>\net1.exe' stop TrkWks
- '<SYSTEM32>\net1.exe' stop TrkWsk
- '<SYSTEM32>\net.exe' stop TrkWsk
- '%WINDIR%\regedit.exe' /s %TEMP%\RarSFX0\sb.reg
- '<SYSTEM32>\net.exe' stop TrkWks
- <SYSTEM32>\est.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\counts[1].asp
- C:\1.htm
- %TEMP%\RarSFX0\Explorer.exe
- %TEMP%\RarSFX0\est.dll
- %TEMP%\RarSFX0\sb.reg
- %TEMP%\RarSFX0\Explorer.exe
- %TEMP%\RarSFX0\sb.reg
- %TEMP%\RarSFX0\est.dll
- 'www.cj##8.net':80
- 'localhost':1035
- www.cj##8.net/cj/counts.asp?id###################
- DNS ASK www.cj##8.net
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'