Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows32kManager' = '%WINDIR%\Temp\win32k.exe'
- %TEMP%\win42.sys
- %TEMP%\win04.bmp
- %TEMP%\win14.scr
- %TEMP%\win05.xml
- %TEMP%\nss2.tmp\blowfish.dll
- %TEMP%\nss2.tmp\inetc.dll
- %TEMP%\nss2.tmp\System.dll
- %TEMP%\nss2.tmp\blowfish.dll
- %TEMP%\nss2.tmp\inetc.dll
- %TEMP%\nss2.tmp\System.dll
- '10#.#72.3.178':545