Technical Information
- '%ProgramFiles%\9158chat_976479.exe' (downloaded from the Internet)
- '%ProgramFiles%\9158chat_976479.exe' /sp- /verysilent /suppressmsgboxes /norestart
- %ProgramFiles%\9158chat_976479.exe
- %TEMP%\~DF58B8.tmp
- 'do####ad.100hdy.cn':80
- 'localhost':1037
- http://do####ad.100hdy.cn/9158/9158chat_976479.exe
- DNS ASK do####ad.100hdy.cn