Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\lsUDRNHi.lnk
- '%TEMP%\contemp.exe' all -oN
- '%TEMP%\pll.exe'
- '%TEMP%\contemp.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /cEcho off & del /q %TEMP%\contemp.exe & Exit
- %TEMP%\contemp.exe
- %ALLUSERSPROFILE%\Application Data\WindowsApplication75\WindowsApplication75\1.0.0.0\screenshot1.bmp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\PWD[1].jpg
- %TEMP%\pll.exe
- %APPDATA%\lsUDRNHigX.exe
- %APPDATA%\lsUDRNHigX.exe
- %TEMP%\contemp.exe
- %APPDATA%\lsUDRNHigX.exe
- %APPDATA%\lsUDRNHigX.exe
- 'en####top.website':80
- 'sm##.gmail.com':587
- http://en####top.website/PWD.jpg
- DNS ASK en####top.website
- DNS ASK sm##.gmail.com
- ClassName: 'Shell_TrayWnd' WindowName: ''