Technical Information
- '%APPDATA%\<Virus name>.exe'
- '%APPDATA%\<Virus name>.exe' (downloaded from the Internet)
- %APPDATA%\<Virus name>.exe
- 'do##.##bantianxia.com':80
- 'localhost':1039
- do##.##bantianxia.com/download/cpa.exe
- DNS ASK do##.##bantianxia.com
- ClassName: 'Shell_TrayWnd' WindowName: ''