Technical Information
- '%TEMP%\nss3.tmp\ns5.tmp' sc stop OtherSearch
- '%TEMP%\nss3.tmp\ns4.tmp' sc.exe query
- '<SYSTEM32>\sc.exe' stop OtherSearch
- '<SYSTEM32>\sc.exe' query
- iexplore.exe
- opera.exe
- firefox.exe
- chrome.exe
- C:\END
- %TEMP%\nsl2.tmp
- %TEMP%\nss3.tmp\ns4.tmp
- 'www.cl###radds.com':80
- http://www.cl###radds.com/ext/
- DNS ASK www.cl###radds.com