Technical Information
- '%TEMP%\gjkq.exe' x wkqN.zip -pq1w2e3r4t5y6u7i8o9 -y
- '%TEMP%\gjkq.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /k c: & cd\ & cd %HOMEPATH%\Local Settings\Temp & gjkq.exe x wkqN.zip -pq1w2e3r4t5y6u7i8o9 -y & exit
- %TEMP%\wkqN.zip
- %TEMP%\gjkq.exe
- 'www.me###nettes.com':80
- http://www.me###nettes.com/content/modules/1-9/chin/chin/chimbinha.jpg
- http://www.me###nettes.com/content/modules/1-9/chin/chin/7za.jpg
- DNS ASK www.me###nettes.com
- ClassName: 'MS_WINHELP' WindowName: ''