Technical Information
- 'C:\G1023_s_80469.exe'
- 'C:\kuyouxi.exe'
- 'C:\F1023_s_40380.exe'
- 'C:\kuyouxi.exe' (downloaded from the Internet)
- 'C:\F1023_s_40380.exe' (downloaded from the Internet)
- 'C:\G1023_s_80469.exe' (downloaded from the Internet)
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\ntvdm.exe' -f -i1
- C:\jKAVSETUPS_60_306522.exe
- C:\kuyouxi.exe
- C:\see_3102-23046.exe
- C:\install1148140.exe
- C:\Browser_V3.1.1644.34_r_4421_(Build14103117).exe
- C:\dudu_b_55226.exe
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- <Current directory>\sa.exe
- C:\V7_79005_20141127150738.exe
- C:\G1023_s_80469.exe
- C:\F1023_s_40380.exe
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- 'cd##xg.com':80
- 'localhost':1039
- cd##xg.com/dudu_b_55226.exe
- cd##xg.com/jKAVSETUPS_60_306522.exe
- cd##xg.com/install1148140.exe
- cd##xg.com/Browser_V3.1.1644.34_r_4421_(Build14103117).exe
- cd##xg.com/kuyouxi.exe
- cd##xg.com/G1023_s_80469.exe
- cd##xg.com/F1023_s_40380.exe
- cd##xg.com/see_3102-23046.exe
- cd##xg.com/V7_79005_20141127150738.exe
- DNS ASK cd##xg.com
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b4c.b50.380001'