Technical Information
- ClassName: 'TXGuiFoundation', WindowName: '???????? - ????????????'
- ClassName: 'TXGuiFoundation', WindowName: 'µзДФ№ЬјТ - НшВзБчБї№ЬАн'
- %APPDATA%\Windows.hlp
- %APPDATA%\Microsoft\Media Player\slvmb\VBS.vbs
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\baidu[1]
- %APPDATA%\Microsoft\Media Player\slvmb\svohost.exe
- %APPDATA%\Microsoft\Media Player\slvmb\VBS.vbs
- <Full path to file>
- from %APPDATA%\Windows.hlp to %APPDATA%\Microsoft\Media Player\slvmb\svohost.exe
- '23.##5.154.146':5200
- '12#.#25.114.144':80
- '<LOCALNET>.0.2':0
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK www.ba##u.com
- '%APPDATA%\Windows.hlp'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file>
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Microsoft\Media Player\slvmb\VBS.vbs"