Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '<File name>.exe' = '<Full path to file>'
- C:\users\public\documents\netuser.tmp
- <Full path to file>
- '43.##9.230.206':12366
- 'wh###.#conline.com.cn':80
- http://wh###.#conline.com.cn/jsFunction.jsp
- '43.##9.230.206':12366
- DNS ASK wh###.#conline.com.cn