Technical Information
- <SYSTEM32>\setup.exe with <SYSTEM32>\Setup.exe
- '<SYSTEM32>\Setup.exe' (downloaded from the Internet)
- <SYSTEM32>\setup.exe
- 'www.zh###an99.com':80
- www.zh###an99.com/log.jpg
- DNS ASK www.zh###an99.com
- ClassName: 'ZElementClient Window' WindowName: 'Element Client'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'msctls_updown32' WindowName: ''