Technical Information
- [<HKLM>\SOFTWARE\Classes\VBEFile\Shell\Open\Command] '' = '<SYSTEM32>\WScript.exe "%1" %*'
- '%TEMP%\~vsxjfif.vbe' "<SYSTEM32>\<File name>.vbe"
- <SYSTEM32>\<File name>.vbe
- %TEMP%\~vsxjfif.vbe
- %TEMP%\aut1.tmp
- <SYSTEM32>\<File name>.vbe
- %TEMP%\~vsxjfif.vbe
- <SYSTEM32>\<File name>.vbe
- %TEMP%\aut1.tmp
- 'pa###bin.com':443
- 'localhost':1037
- DNS ASK pa###bin.com