Technical Information
- <PATH_SAMPLE>.bak
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- <Full path to file>
- <Full path to file>
- <PATH_SAMPLE>.bak
- <Full path to file>
- 'li###anqj.com':88
- 'localhost':9960
- http://www.li####nqj.com:88/update/Init.txt via li###anqj.com
- http://www.li####nqj.com:88/update/up.exe via li###anqj.com
- http://www.li####nqj.com:88/gg.htm via li###anqj.com
- http://www.li####nqj.com:88/gg_files/mu.css via li###anqj.com
- http://www.li####nqj.com:88/gg_files/bg.gif via li###anqj.com
- DNS ASK li###anqj.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<Full path to file>'
- '%WINDIR%\syswow64\cmd.exe' /c del <File name>.exe & ping 127.0.0.1 & ren <File name>.BAK <File name>.exe & start <File name>.exe
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /c del <File name>.exe & ping 127.0.0.1 & ren <File name>.BAK <File name>.exe & start <File name>.exe' (with hidden window)