Technical Information
- "%TEMP%\~!09wxe09.tmp" (downloaded from the Internet)
- "%TEMP%\~!09wte09.tmp" (downloaded from the Internet)
- "%TEMP%\~!0958e09.tmp" (downloaded from the Internet)
- "%TEMP%\~!09wee09.tmp" (downloaded from the Internet)
- <SYSTEM32>\spoolsv.exe
- %TEMP%\~!09wxe09.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\2[1].bin
- %TEMP%\~!09wte09.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\3[1].bin
- %TEMP%\~!09wee09.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\4[1].bin
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\chaji[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\1[1].bin
- %TEMP%\~!0958e09.tmp
- 'localhost':1038
- 'sb.##fabcd.info':80
- 'localhost':1035
- 'www.dn##1.com':80
- sb.##fabcd.info/chaji/2.bin
- sb.##fabcd.info/chaji/3.bin
- sb.##fabcd.info/chaji/1.bin
- www.dn##1.com/mfsm/chaji/chaji.htm
- sb.##fabcd.info/chaji/4.bin
- DNS ASK sb.##fabcd.info
- DNS ASK www.dn##1.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''