Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LeyuBoxData' = ''
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'KingSoft PowerWord PE' = ''
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ÍøÂçµçÊÓ' = ''
- <Current directory>\$$del$$.bat
- DNS ASK up.###ritsoft.cn
- ClassName: '' WindowName: '¹È¸è½ðɽ´Ê°ÔºÏ×÷°æ2.0 °²×°'
- ClassName: '' WindowName: '¹È¸è½ðɽ´Ê°ÔºÏ×÷°æ2.0 °²×° '
- ClassName: '' WindowName: '¹È¸è½ðɽ´Ê°Ô2.0 ÉèÖÃÏòµ¼'
- ClassName: '' WindowName: '¹È¸è½ðɽ´Ê°ÔºÏ×÷°æ °²×°'
- ClassName: '#32770' WindowName: ''
- ClassName: '' WindowName: '¹È¸è½ðɽ´Ê°ÔºÏ×÷°æ °²×° '
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\$$del$$.bat
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\$$del$$.bat' (with hidden window)