Technical Information
- 'C:\li.exe'
- 'C:\pk.exe'
- 'C:\li.exe' (downloaded from the Internet)
- 'C:\pk.exe' (downloaded from the Internet)
- NtWriteVirtualMemory, handler: pk.sys
- NtReadVirtualMemory, handler: pk.sys
- NtQuerySystemInformation, handler: pk.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\oqhL1[1]
- C:\li.exe
- <Current directory>\pk.sys
- C:\pk.exe
- 'www.dn###ilong.com':80
- 'ur#7.me':80
- 'localhost':1035
- www.dn###ilong.com/yuankong.bin
- www.dn###ilong.com/pk.bin
- ur#7.me/oqhL1
- DNS ASK www.dn###ilong.com
- DNS ASK ur#7.me
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '????????????' WindowName: '????????????'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'