Technical Information
- <Current directory>\yihahago.exe (downloaded from the Internet)
- <Current directory>\click.exe
- <Current directory>\yihahago.exe
- <Current directory>\tem.bak
- <Current directory>\gorun.exe
- <Current directory>\tem.bak
- 'ip.##haha.org':80
- ip.##haha.org/soft/yihahago.exe
- ip.##haha.org/soft/click.exe
- ip.##haha.org/soft/gorun.exe
- DNS ASK ip.##haha.org
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''