Technical Information
- %ALLUSERSPROFILE%\xis\ogrbab.cwx
- %TEMP%\gfa.beb
- <Full path to file>
- from <Full path to file> to %TEMP%\1.tmp
- 'fr###chesin.com':80
- http://ca##ax.com/guo1l2p4q/index.php via fr###chesin.com
- http://ze##er.com/guo1l2p4q/index.php via fr###chesin.com
- DNS ASK microsoft.com
- DNS ASK ee###difens.com
- DNS ASK fr###chesin.com
- DNS ASK google.com
- '%ProgramFiles%\Windows Media Player\wmplayer.exe'