Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'THUpdate' = ''
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\Microsoft\Network\rasphone.dll",Update
- %APPDATA%\Microsoft\Network\6B5A4606.CAB
- %TEMP%\request.doc
- %TEMP%\00EL2253C.TMP
- %TEMP%\svahost.dat
- %APPDATA%\Microsoft\Network\rasphone.dll
- 'www.im##ju.com':443
- '18#.#2.44.209':8080
- 'www.im##ju.net':443
- 'cy###.imonju.com':443
- 'www.im##ju.net':80
- www.im##ju.net/1/archive/00561611.html
- DNS ASK www.im##ju.com
- DNS ASK www.im##ju.net
- DNS ASK cy###.imonju.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'WordPadClass' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'