Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '11f86284' = '%APPDATA%\ZTaskGen\taskgen.exe'
- '%APPDATA%\ZTaskGen\taskgen.exe'
- '<SYSTEM32>\cmd.exe' /v/c (set f="<Full path to file>"&for /l %l in () do if exist !f! (del /f/a !f!) else (exit))
- taskgen.exe
- %APPDATA%\ZTaskGen\taskgen.exe
- 'au####istory.net':80
- 'id######craftseating.com':80
- 'www.ya###ashop.com':80
- http://au####istory.net/wp-content/plugins/WPSecurity/load.php
- http://id######craftseating.com/wp-content/plugins/WPSecurity/load.php
- http://www.ya###ashop.com/wp-content/plugins/WPSecurity/load.php
- DNS ASK au####istory.net
- DNS ASK id######craftseating.com
- DNS ASK www.ya###ashop.com